CVE-2010-3702
published 2010-11-05CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.76%
84.6th percentile
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.11 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | poppler | < poppler 0.12.4-1.2 (bookworm) | poppler 0.12.4-1.2 (bookworm) |
| debian | xpdf | < poppler 0.12.4-1.2 (bookworm) | poppler 0.12.4-1.2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | 0.8.7 – 0.15.1 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2010-10-19
CVE-2010-3702 poppler vulnerabilities
Title: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
xpdf: uninitialized Gfx::parser pointer dereference
vendor_redhat·2010-09-24·CVSS 7.5
CVE-2010-3702 [HIGH] xpdf: uninitialized Gfx::parser pointer dereference
xpdf: uninitialized Gfx::parser pointer dereference
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
Package: tetex (Red Hat Enterprise Linux 4) - Affected
Debian
CVE-2010-3702: poppler - The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7...
vendor_debian·2010·CVSS 7.5
CVE-2010-3702 [HIGH] CVE-2010-3702: poppler - The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7...
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.12.4-1.2)
bullseye: resolved (fixed in 0.12.4-1.2)
forky: resolved (fixed in 0.12.4-1.2)
sid: resolved (fixed in 0.12.4-1.2)
trixie: resolved (fixed in 0.12.4-1.2)
GHSA
GHSA-89fq-mfqc-jvjp: The Gfx::getPos function in the PDF parser in xpdf before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3702 [HIGH] CWE-476 GHSA-89fq-mfqc-jvjp: The Gfx::getPos function in the PDF parser in xpdf before 3
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
OSV
CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3
osv·2010-11-05·CVSS 7.5
CVE-2010-3702 [HIGH] CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
No detection rules found.
No public exploits indexed.
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patchhttp://cgit.freedesktop.org/poppler/poppler/commit/?id=e853106b58d6b4b0467dbd6436c9bb1cfbd372cfhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1201.htmlhttp://secunia.com/advisories/42141http://secunia.com/advisories/42357http://secunia.com/advisories/42397http://secunia.com/advisories/42691http://secunia.com/advisories/43079http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720http://www.debian.org/security/2010/dsa-2119http://www.debian.org/security/2010/dsa-2135http://www.mandriva.com/security/advisories?name=MDVSA-2010:228http://www.mandriva.com/security/advisories?name=MDVSA-2010:229http://www.mandriva.com/security/advisories?name=MDVSA-2010:230http://www.mandriva.com/security/advisories?name=MDVSA-2010:231http://www.mandriva.com/security/advisories?name=MDVSA-2012:144http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.htmlhttp://www.openwall.com/lists/oss-security/2010/10/04/6http://www.redhat.com/support/errata/RHSA-2010-0749.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0750.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0751.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0752.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0753.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0754.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0755.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0859.htmlhttp://www.securityfocus.com/bid/43845http://www.ubuntu.com/usn/USN-1005-1http://www.vupen.com/english/advisories/2010/2897http://www.vupen.com/english/advisories/2010/3097http://www.vupen.com/english/advisories/2011/0230https://bugzilla.redhat.com/show_bug.cgi?id=595245ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patchhttp://cgit.freedesktop.org/poppler/poppler/commit/?id=e853106b58d6b4b0467dbd6436c9bb1cfbd372cfhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1201.htmlhttp://secunia.com/advisories/42141http://secunia.com/advisories/42357http://secunia.com/advisories/42397http://secunia.com/advisories/42691http://secunia.com/advisories/43079http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720http://www.debian.org/security/2010/dsa-2119http://www.debian.org/security/2010/dsa-2135http://www.mandriva.com/security/advisories?name=MDVSA-2010:228http://www.mandriva.com/security/advisories?name=MDVSA-2010:229http://www.mandriva.com/security/advisories?name=MDVSA-2010:230http://www.mandriva.com/security/advisories?name=MDVSA-2010:231http://www.mandriva.com/security/advisories?name=MDVSA-2012:144http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.htmlhttp://www.openwall.com/lists/oss-security/2010/10/04/6http://www.redhat.com/support/errata/RHSA-2010-0749.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0750.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0751.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0752.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0753.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0754.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0755.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0859.htmlhttp://www.securityfocus.com/bid/43845http://www.ubuntu.com/usn/USN-1005-1http://www.vupen.com/english/advisories/2010/2897http://www.vupen.com/english/advisories/2010/3097http://www.vupen.com/english/advisories/2011/0230https://bugzilla.redhat.com/show_bug.cgi?id=595245
2010-11-05
Published