CVE-2008-2950
EPSS 12.3%poppler - arbitrary code execution
Published: 7/7/2008Modified: 4/28/2026
Description
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.
Affected packages (2)
- Debian/popplerfrom 0, < 0.8.4-1.1
- Debian/popplerfrom 0, < 0.8.2-2+lenny1