cbcvebase.
CVE-2010-3703
published 2010-11-05

CVE-2010-3703: The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and…

medium4.3CVSS 3.1
AVNACMAuNCNINAP
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianpoppler< poppler 0.12.4-1.2 (bookworm)poppler 0.12.4-1.2 (bookworm)
debianxpdf< poppler 0.12.4-1.2 (bookworm)poppler 0.12.4-1.2 (bookworm)
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
freedesktoppoppler>= 0 < 0.12.4-1.20.12.4-1.2
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM