CVE-2010-3702
xpdf - several vulnerabilities
EPSS 9.2%
Description
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
How to fix CVE-2010-3702
To remediate CVE-2010-3702, upgrade the affected package to a fixed version below.
- Debian/poppler—upgrade to 0.12.4-1.2 or later
- Debian/poppler—upgrade to 0.8.7-4 or later
- —upgrade to 3.02-9 or later
- —upgrade to 3.02-1.4+lenny3 or later
Is CVE-2010-3702 being exploited?
Moderate — EPSS is 9.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (4)
- from 0, < 0.12.4-1.2
- from 0, < 0.8.7-4
- from 0, < 3.02-9
- from 0, < 3.02-1.4+lenny3