CVE-2010-3703
published 2010-11-05CVE-2010-3703: The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.56%
83.3th percentile
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.4-1.2 (bookworm) | poppler 0.12.4-1.2 (bookworm) |
| debian | xpdf | < poppler 0.12.4-1.2 (bookworm) | poppler 0.12.4-1.2 (bookworm) |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgg5-h322-m2xw: The PostScriptFunction::PostScriptFunction function in poppler/Function
ghsa_unreviewed·2022-05-17
CVE-2010-3703 [MEDIUM] CWE-20 GHSA-qgg5-h322-m2xw: The PostScriptFunction::PostScriptFunction function in poppler/Function
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.
OSV
CVE-2010-3703: The PostScriptFunction::PostScriptFunction function in poppler/Function
osv·2010-11-05·CVSS 4.3
CVE-2010-3703 [MEDIUM] CVE-2010-3703: The PostScriptFunction::PostScriptFunction function in poppler/Function
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2010-10-19
CVE-2010-3702 poppler vulnerabilities
Title: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
poppler: use of initialized pointer in PostScriptFunction
vendor_redhat·2010-09-24·CVSS 4.3
CVE-2010-3703 [MEDIUM] poppler: use of initialized pointer in PostScriptFunction
poppler: use of initialized pointer in PostScriptFunction
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.
Package: poppler (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2010-3703: poppler - The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in th...
vendor_debian·2010·CVSS 4.3
CVE-2010-3703 [MEDIUM] CVE-2010-3703: poppler - The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in th...
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.12.4-1.2)
bullseye: resolved (fixed in 0.12.4-1.2)
forky: resolved (fixed in 0.12.4-1.2)
sid: resolved (fixed in 0.12.4-1.2)
trixie: resolved (fixed in 0.12.4-1.2)
No detection rules found.
No public exploits indexed.
http://cgit.freedesktop.org/poppler/poppler/commit/?id=bf2055088a3a2d3bb3d3c37d464954ec1a25771fhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://secunia.com/advisories/42357http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720http://www.mandriva.com/security/advisories?name=MDVSA-2010:231http://www.openwall.com/lists/oss-security/2010/10/04/6http://www.redhat.com/support/errata/RHSA-2010-0859.htmlhttp://www.ubuntu.com/usn/USN-1005-1https://bugzilla.redhat.com/show_bug.cgi?id=639356http://cgit.freedesktop.org/poppler/poppler/commit/?id=bf2055088a3a2d3bb3d3c37d464954ec1a25771fhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://secunia.com/advisories/42357http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720http://www.mandriva.com/security/advisories?name=MDVSA-2010:231http://www.openwall.com/lists/oss-security/2010/10/04/6http://www.redhat.com/support/errata/RHSA-2010-0859.htmlhttp://www.ubuntu.com/usn/USN-1005-1https://bugzilla.redhat.com/show_bug.cgi?id=639356
2010-11-05
Published