PT-2010-5013 · Poppler+1 · Poppler+1
Tomas Hoger
·
Published
2010-10-13
·
Updated
2011-01-22
·
CVE-2010-3703
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
poppler versions 0.8.7 through 0.15.1
Description
The issue allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference in the PostScriptFunction::PostScriptFunction function.
Recommendations
For versions 0.8.7 through 0.15.1, consider disabling the PostScriptFunction::PostScriptFunction function until a patch is available. Restrict access to PDF files from untrusted sources to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Poppler