CVE-2010-3702
EPSS 4.7%xpdf - several vulnerabilities
Published: 11/5/2010Modified: 4/28/2026
Also known as:DEBIAN-CVE-2010-3702
Description
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
Affected packages (4)
- Debian/popplerfrom 0, < 0.12.4-1.2
- Debian/popplerfrom 0, < 0.8.7-4
- Debian/xpdffrom 0, < 3.02-9
- Debian/xpdffrom 0, < 3.02-1.4+lenny3