6.8
CVSSv2

CVE-2013-1788

Published: 09/04/2013 Updated: 28/01/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

poppler prior to 0.22.1 allows context-dependent malicious users to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler

Vendor Advisories

Applications using poppler could be made to crash or possibly run programs as your login if they opened a specially crafted file ...
Debian Bug report logs - #702071 CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790 Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Mar 2013 12:51:01 UTC Severity: grav ...
Multiple vulnerabilities were discovered in the poppler PDF rendering library CVE-2013-1788 Multiple invalid memory access issues, which could potentially lead to arbitrary code execution if the user were tricked into opening a malformed PDF document CVE-2013-1790 An uninitialized memory issue, which could potentially lead to ...