CVE-2010-3704
published 2010-11-05CVE-2010-3704: The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.60%
88.2th percentile
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.4-1.2 (bookworm) | poppler 0.12.4-1.2 (bookworm) |
| debian | xpdf | < poppler 0.12.4-1.2 (bookworm) | poppler 0.12.4-1.2 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| freedesktop | poppler | >= 0 < 0.12.4-1.2 | 0.12.4-1.2 |
| glyphandcog | xpdfreader | <= 3.02 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwg7-7mhm-4945: The FoFiType1::parse function in fofi/FoFiType1
ghsa_unreviewed·2022-05-17
CVE-2010-3704 [MEDIUM] CWE-20 GHSA-fwg7-7mhm-4945: The FoFiType1::parse function in fofi/FoFiType1
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
OSV
CVE-2010-3704: The FoFiType1::parse function in fofi/FoFiType1
osv·2010-11-05·CVSS 6.8
CVE-2010-3704 [MEDIUM] CVE-2010-3704: The FoFiType1::parse function in fofi/FoFiType1
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2010-10-19
CVE-2010-3702 poppler vulnerabilities
Title: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
xpdf: array indexing error in FoFiType1::parse()
vendor_redhat·2010-09-24·CVSS 6.8
CVE-2010-3704 [MEDIUM] xpdf: array indexing error in FoFiType1::parse()
xpdf: array indexing error in FoFiType1::parse()
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
Package: cups (Red Hat Enterprise Linux 4) - Not affected
Package: tetex (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2010-3704: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf bef...
vendor_debian·2010·CVSS 6.8
CVE-2010-3704 [MEDIUM] CVE-2010-3704: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf bef...
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
Scope: local
bookworm: resolved (fixed in 0.12.4-1.2)
bullseye: resolved (fixed in 0.12.4-1.2)
forky: resolved (fixed in 0.12.4-1.2)
sid: resolved (fixed in 0.12.4-1.2)
trixie: resolved (fixed in 0.12.4-1.2)
No detection rules found.
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patchhttp://cgit.freedesktop.org/poppler/poppler/commit/?id=39d140bfc0b8239bdd96d6a55842034ae5c05473http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1201.htmlhttp://secunia.com/advisories/42141http://secunia.com/advisories/42357http://secunia.com/advisories/42397http://secunia.com/advisories/42691http://secunia.com/advisories/43079http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720http://www.debian.org/security/2010/dsa-2119http://www.debian.org/security/2010/dsa-2135http://www.mandriva.com/security/advisories?name=MDVSA-2010:228http://www.mandriva.com/security/advisories?name=MDVSA-2010:229http://www.mandriva.com/security/advisories?name=MDVSA-2010:230http://www.mandriva.com/security/advisories?name=MDVSA-2010:231http://www.mandriva.com/security/advisories?name=MDVSA-2012:144http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.htmlhttp://www.openwall.com/lists/oss-security/2010/10/04/6http://www.redhat.com/support/errata/RHSA-2010-0749.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0751.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0752.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0753.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0859.htmlhttp://www.securityfocus.com/bid/43841http://www.ubuntu.com/usn/USN-1005-1http://www.vupen.com/english/advisories/2010/2897http://www.vupen.com/english/advisories/2010/3097http://www.vupen.com/english/advisories/2011/0230https://bugzilla.redhat.com/show_bug.cgi?id=638960ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patchhttp://cgit.freedesktop.org/poppler/poppler/commit/?id=39d140bfc0b8239bdd96d6a55842034ae5c05473http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1201.htmlhttp://secunia.com/advisories/42141http://secunia.com/advisories/42357http://secunia.com/advisories/42397http://secunia.com/advisories/42691http://secunia.com/advisories/43079http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720http://www.debian.org/security/2010/dsa-2119http://www.debian.org/security/2010/dsa-2135http://www.mandriva.com/security/advisories?name=MDVSA-2010:228http://www.mandriva.com/security/advisories?name=MDVSA-2010:229http://www.mandriva.com/security/advisories?name=MDVSA-2010:230http://www.mandriva.com/security/advisories?name=MDVSA-2010:231http://www.mandriva.com/security/advisories?name=MDVSA-2012:144http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.htmlhttp://www.openwall.com/lists/oss-security/2010/10/04/6http://www.redhat.com/support/errata/RHSA-2010-0749.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0751.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0752.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0753.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0859.htmlhttp://www.securityfocus.com/bid/43841http://www.ubuntu.com/usn/USN-1005-1http://www.vupen.com/english/advisories/2010/2897http://www.vupen.com/english/advisories/2010/3097http://www.vupen.com/english/advisories/2011/0230https://bugzilla.redhat.com/show_bug.cgi?id=638960
2010-11-05
Published