CVE-2008-2950
EPSS 12.3%poppler - arbitrary code execution
發布日:2008/7/7修改日:2026/4/28
描述
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.
受影響套件(2)
- Debian/popplerfrom 0, < 0.8.4-1.1
- Debian/popplerfrom 0, < 0.8.2-2+lenny1