CVE-2010-3704

Description

The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.533

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2010:0749) Important: poppler security update poppler-0.5.4-4.4.el5_5.14.i386.rpmLinux
(RHSA-2010:0749) Important: poppler security update poppler-0.5.4-4.4.el5_5.14.x86_64.rpmLinux
(RHSA-2010:0749) Important: poppler security update poppler-devel-0.5.4-4.4.el5_5.14.i386.rpmLinux
(RHSA-2010:0749) Important: poppler security update poppler-devel-0.5.4-4.4.el5_5.14.x86_64.rpmLinux
(RHSA-2010:0749) Important: poppler security update poppler-utils-0.5.4-4.4.el5_5.14.i386.rpmLinux
(RHSA-2010:0749) Important: poppler security update poppler-utils-0.5.4-4.4.el5_5.14.x86_64.rpmLinux
(RHSA-2010:0753) Important: kdegraphics security update kdegraphics-3.5.4-17.el5_5.1.i386.rpmLinux
(RHSA-2010:0753) Important: kdegraphics security update kdegraphics-3.5.4-17.el5_5.1.x86_64.rpmLinux
(RHSA-2010:0753) Important: kdegraphics security update kdegraphics-devel-3.5.4-17.el5_5.1.i386.rpmLinux
(RHSA-2010:0753) Important: kdegraphics security update kdegraphics-devel-3.5.4-17.el5_5.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-3.0-33.15.el5_8.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-afm-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-afm-3.0-33.15.el5_8.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-doc-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-doc-3.0-33.15.el5_8.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-dvips-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-dvips-3.0-33.15.el5_8.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-fonts-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-fonts-3.0-33.15.el5_8.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-latex-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-latex-3.0-33.15.el5_8.1.x86_64.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-xdvi-3.0-33.15.el5_8.1.i386.rpmLinux
(RHSA-2012:1201) Moderate: tetex security update tetex-xdvi-3.0-33.15.el5_8.1.x86_64.rpmLinux
Poppler update (ELSA-2024-2979) poppler-20.11.0-11.el8.i686.rpmLinux
Poppler update (ELSA-2024-2979) poppler-20.11.0-11.el8.x86_64.rpmLinux
Poppler-glib update (ELSA-2024-2979) poppler-glib-20.11.0-11.el8.i686.rpmLinux
Poppler-glib update (ELSA-2024-2979) poppler-glib-20.11.0-11.el8.x86_64.rpmLinux
Poppler-qt5 update (ELSA-2024-2979) poppler-qt5-20.11.0-11.el8.i686.rpmLinux
Poppler-qt5 update (ELSA-2024-2979) poppler-qt5-20.11.0-11.el8.x86_64.rpmLinux
Poppler-utils update (ELSA-2024-2979) poppler-utils-20.11.0-11.el8.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234