CVE-2010-2575
EPSS 4.7%
Description
Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.
How to fix CVE-2010-2575
To remediate CVE-2010-2575, upgrade the affected package to a fixed version below.
- Debian/okular—upgrade to 4:4.4.5-2 or later
Is CVE-2010-2575 being exploited?
Low — EPSS is 4.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4:4.4.5-2