CVE-2010-3702
Description
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
Risk Information
Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.916
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2010:0749) Important: poppler security update poppler-0.5.4-4.4.el5_5.14.i386.rpm | Linux |
| (RHSA-2010:0749) Important: poppler security update poppler-0.5.4-4.4.el5_5.14.x86_64.rpm | Linux |
| (RHSA-2010:0749) Important: poppler security update poppler-devel-0.5.4-4.4.el5_5.14.i386.rpm | Linux |
| (RHSA-2010:0749) Important: poppler security update poppler-devel-0.5.4-4.4.el5_5.14.x86_64.rpm | Linux |
| (RHSA-2010:0749) Important: poppler security update poppler-utils-0.5.4-4.4.el5_5.14.i386.rpm | Linux |
| (RHSA-2010:0749) Important: poppler security update poppler-utils-0.5.4-4.4.el5_5.14.x86_64.rpm | Linux |
| (RHSA-2010:0753) Important: kdegraphics security update kdegraphics-3.5.4-17.el5_5.1.i386.rpm | Linux |
| (RHSA-2010:0753) Important: kdegraphics security update kdegraphics-3.5.4-17.el5_5.1.x86_64.rpm | Linux |
| (RHSA-2010:0753) Important: kdegraphics security update kdegraphics-devel-3.5.4-17.el5_5.1.i386.rpm | Linux |
| (RHSA-2010:0753) Important: kdegraphics security update kdegraphics-devel-3.5.4-17.el5_5.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-afm-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-afm-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-doc-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-doc-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-dvips-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-dvips-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-fonts-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-fonts-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-latex-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-latex-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-xdvi-3.0-33.15.el5_8.1.i386.rpm | Linux |
| (RHSA-2012:1201) Moderate: tetex security update tetex-xdvi-3.0-33.15.el5_8.1.x86_64.rpm | Linux |
| Poppler update (ELSA-2024-2979) poppler-20.11.0-11.el8.i686.rpm | Linux |
| Poppler update (ELSA-2024-2979) poppler-20.11.0-11.el8.x86_64.rpm | Linux |
| Poppler-glib update (ELSA-2024-2979) poppler-glib-20.11.0-11.el8.i686.rpm | Linux |
| Poppler-glib update (ELSA-2024-2979) poppler-glib-20.11.0-11.el8.x86_64.rpm | Linux |
| Poppler-qt5 update (ELSA-2024-2979) poppler-qt5-20.11.0-11.el8.i686.rpm | Linux |
| Poppler-qt5 update (ELSA-2024-2979) poppler-qt5-20.11.0-11.el8.x86_64.rpm | Linux |
| Poppler-utils update (ELSA-2024-2979) poppler-utils-20.11.0-11.el8.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234