Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-50422 — Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF streams from process memory. | Kitploit
Tools/GitHubGitHub/landw-hub/cve-2025-50422
Memory ForensicsVulnerability AnalysisExploitationForensicsData RecoveryDigital Forensics
GitHublandw-hub/cve-2025-50422

CVE-2025-50422

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF streams from process memory.

View Repository
1136 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Poppler before version 25.04.0

When pdftocairo renders a malicious PDF and calls cairo_debug_reset_static_data() on exit, heap memory containing PDF object streams is not properly cleared. An attacker with local access can dump process memory and recover clear-text PDF content (e.g., /stream /endstream blocks).

The specific vulnerability reproduction process(Cause of the vulnerability.pdf) and POC file(poppler-pdftocairo-poc) are attached.

The vendor (freedesktop, maintainer of Poppler) has acknowledged the issue and fixed the bug. The fix has been committed in their official repository.

Here is the public link to the patch / commit provided by the vendor:

https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591
https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621

This confirms that the vulnerability has been acknowledged and remediated.

Poppler 25.04.0 版本之前

当 pdftocairo 渲染恶意 PDF 并在退出时调用 cairo_debug_reset_static_data() 时,包含 PDF 对象流的堆内存未被正确清除。具有本地访问权限的攻击者可以转储进程内存并恢复明文 PDF 内容(例如 /stream /endstream 块)。

具体的漏洞复现过程(漏洞原因.pdf)和 POC 文件(poppler-pdftocairo-poc)已附上。

供应商(freedesktop,Poppler 的维护者)已确认此问题并修复了该漏洞。修复程序已提交到其官方代码库。

以下是供应商提供的补丁/提交的公开链接:

https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591

https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621

这证实了该漏洞已被确认并修复。

Download Tool