4.3
CVSSv2

CVE-2013-1789

Published: 09/04/2013 Updated: 10/04/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

splash/Splash.cc in poppler prior to 0.22.1 allows context-dependent malicious users to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler

Vendor Advisories

Debian Bug report logs - #702071 CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790 Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Mar 2013 12:51:01 UTC Severity: grav ...
Applications using poppler could be made to crash or possibly run programs as your login if they opened a specially crafted file ...