4.3
CVSSv2

CVE-2010-3703

Published: 05/11/2010 Updated: 22/01/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent malicious users to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

poppler poppler 0.9.0

poppler poppler 0.9.1

poppler poppler 0.10.4

poppler poppler 0.10.5

poppler poppler 0.12.0

poppler poppler 0.12.1

poppler poppler 0.13.3

poppler poppler 0.13.4

poppler poppler 0.14.0

poppler poppler 0.15.1

poppler poppler 0.10.2

poppler poppler 0.10.3

poppler poppler 0.11.2

poppler poppler 0.11.3

poppler poppler 0.13.1

poppler poppler 0.13.2

poppler poppler 0.14.5

poppler poppler 0.15.0

poppler poppler 0.10.0

poppler poppler 0.10.1

poppler poppler 0.11.0

poppler poppler 0.11.1

poppler poppler 0.12.4

poppler poppler 0.13.0

poppler poppler 0.14.3

poppler poppler 0.14.4

poppler poppler 0.9.2

poppler poppler 0.9.3

poppler poppler 0.8.7

poppler poppler 0.10.6

poppler poppler 0.10.7

poppler poppler 0.12.2

poppler poppler 0.12.3

poppler poppler 0.14.1

poppler poppler 0.14.2

Vendor Advisories

Debian Bug report logs - #599165 poppler: Several security issues Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 5 Oct 2010 09:00:01 UTC Severity: grave Tags: ...
It was discovered that poppler contained multiple security issues when parsing malformed PDF documents If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program ...