cbcvebase.
CVE-2010-3702
published 2010-11-05

CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
applecups<= 1.3.11
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianpoppler< poppler 0.12.4-1.2 (bookworm)poppler 0.12.4-1.2 (bookworm)
debianxpdf< poppler 0.12.4-1.2 (bookworm)poppler 0.12.4-1.2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler0.8.7 – 0.15.1
opensuseopensuse
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH