CVE-2010-3702
EPSS 4.7%xpdf - several vulnerabilities
發布日:2010/11/5修改日:2026/4/28
也稱為:DEBIAN-CVE-2010-3702
描述
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
受影響套件(4)
- Debian/popplerfrom 0, < 0.12.4-1.2
- Debian/popplerfrom 0, < 0.8.7-4
- Debian/xpdffrom 0, < 3.02-9
- Debian/xpdffrom 0, < 3.02-1.4+lenny3