PT-2010-1013 · Freedesktop.Org+4 · Poppler+7

Sauli Pahlman

·

Published

2010-10-07

·

Updated

2020-12-23

·

CVE-2010-3702

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cups versions 1.1.17 through 1.1.22 cups-devel versions 1.1.17 through 1.1.22 cups-libs versions 1.1.17 through 1.1.22 kdegraphics versions 3.3.1 kdegraphics-devel versions 3.3.1 xpdf versions prior to 3.02pl5 poppler versions prior to 0.15.1
Description The issue is related to a vulnerability in the PDF parser, specifically the Gfx::getPos function, which allows context-dependent attackers to cause a denial of service or gain access to confidential data. The vulnerability can be exploited remotely, potentially leading to a disruption of confidentiality, integrity, and availability of protected information.
Recommendations For cups versions 1.1.17 through 1.1.22, consider disabling the vulnerable function until a patch is available. For cups-devel versions 1.1.17 through 1.1.22, restrict access to the vulnerable module to minimize the risk of exploitation. For cups-libs versions 1.1.17 through 1.1.22, avoid using the vulnerable library until the issue is resolved. For kdegraphics versions 3.3.1, consider disabling the vulnerable component until a patch is available. For kdegraphics-devel versions 3.3.1, restrict access to the vulnerable module to minimize the risk of exploitation. For xpdf versions prior to 3.02pl5, update to version 3.02pl5 or later. For poppler versions prior to 0.15.1, update to version 0.15.1 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02166
BDU:2015-06165
BDU:2015-06166
BDU:2015-06167
BDU:2015-06215
BDU:2015-06219
BDU:2015-07178
BDU:2015-07181
BDU:2015-07184
BDU:2015-08551
BDU:2015-08552
BDU:2015-08553
BDU:2015-08625
BDU:2015-08626
BDU:2015-08627
BDU:2015-08628
BDU:2015-08629
CVE-2010-3702
DSA-2119-1
DSA-2135-1
RHSA-2010:0749
RHSA-2010:0750
RHSA-2010:0751
RHSA-2010:0752
RHSA-2010:0753
RHSA-2010:0754
RHSA-2010:0755
RHSA-2010:0859
RHSA-2010_0749
RHSA-2010_0751
RHSA-2010_0752
RHSA-2010_0753
RHSA-2010_0755
RHSA-2010_0859
RHSA-2012:1201
RHSA-2012_1201
USN-1005-1

Affected Products

Red Hat
Cups
Cups-Devel
Cups-Libs
Kdegraphics
Kdegraphics-Devel
Poppler
Xpdf