{"id":"ECHO-ff9b-787b-df82","summary":"The vulnerable code is in the internal JPX decoder\n(JPXStream::readUByte), but Debian builds poppler to use openjpeg instead.\nThe vulnerable code exists in the source but is not used at runtime.\n\nhttps://security-tracker.debian.org/tracker/CVE-2017-9083\n","modified":"2026-09-15T00:47:34.204113838Z","published":"2025-08-29T01:36:58.505336Z","withdrawn":"2025-12-09T15:30:04.042Z","upstream":["CVE-2017-9083"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2017-9083"}],"affected":[{"package":{"name":"poppler","ecosystem":"Echo","purl":"pkg:deb/echo/poppler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.03.0-5+deb13u2+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-ff9b-787b-df82.json"}}],"schema_version":"1.9.0"}