An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-10872 User=admin}