Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsamplerowbox_filter function.
{ "urgency": "not yet assigned" }