4.3
CVSSv2

CVE-2013-1789

Published: 09/04/2013 Updated: 10/04/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

splash/Splash.cc in poppler prior to 0.22.1 allows context-dependent malicious users to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler

Vendor Advisories

Applications using poppler could be made to crash or possibly run programs as your login if they opened a specially crafted file ...
Debian Bug report logs - #702071 CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790 Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Mar 2013 12:51:01 UTC Severity: grav ...