PT-2010-5013 · Poppler+1 · Poppler+1

Tomas Hoger

·

Publicado

2010-10-13

·

Atualizado

2011-01-22

·

CVE-2010-3703

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions poppler versions 0.8.7 through 0.15.1
Description The issue allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference in the PostScriptFunction::PostScriptFunction function.
Recommendations For versions 0.8.7 through 0.15.1, consider disabling the PostScriptFunction::PostScriptFunction function until a patch is available. Restrict access to PDF files from untrusted sources to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3703
RHSA-2010:0859
RHSA-2010_0859
USN-1005-1

Produtos afetados

Red Hat
Poppler