A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
https://usn.ubuntu.com/4042-1/
https://usn.ubuntu.com/3905-1/
https://lists.debian.org/debian-lts-announce/2020/07/msg00018.html
https://lists.debian.org/debian-lts-announce/2019/03/msg00008.html
https://gitlab.freedesktop.org/poppler/poppler/issues/728
https://access.redhat.com/errata/RHSA-2019:2713