Уязвимость CVE-2010-3702: Информация

Описание

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.

Важность: HIGH (7,5)

Опубликовано: 5 ноября 2010 г.
Изменено: 23 декабря 2020 г.
Идентификатор типа ошибки: CWE-476

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
RHSA-2010:0749
  • Third Party Advisory
USN-1005-1
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=595245
  • Issue Tracking
  • Patch
  • Third Party Advisory
http://cgit.freedesktop.org/poppler/poppler/commit/?id=e853106b58d6b4b0467dbd6436c9bb1cfbd372cf
  • Patch
  • Vendor Advisory
FEDORA-2010-15911
  • Third Party Advisory
RHSA-2010:0753
  • Third Party Advisory
RHSA-2010:0751
  • Third Party Advisory
FEDORA-2010-15857
  • Third Party Advisory
RHSA-2010:0752
  • Third Party Advisory
43845
  • Third Party Advisory
  • VDB Entry
DSA-2119
  • Third Party Advisory
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patch
  • Broken Link
RHSA-2010:0750
  • Third Party Advisory
FEDORA-2010-15981
  • Third Party Advisory
[oss-security] 20101004 Re: CVE requests: Poppler, Quassel, Pyfribidi, Overkill, DocUtils, FireGPG, Wireshark
  • Mailing List
  • Patch
  • Third Party Advisory
ADV-2010-2897
  • Third Party Advisory
FEDORA-2010-16744
  • Third Party Advisory
FEDORA-2010-16705
  • Third Party Advisory
FEDORA-2010-16662
  • Third Party Advisory
42141
  • Third Party Advisory
RHSA-2010:0754
  • Third Party Advisory
MDVSA-2010:230
  • Third Party Advisory
SUSE-SR:2010:022
  • Mailing List
  • Third Party Advisory
42397
  • Third Party Advisory
MDVSA-2010:229
  • Third Party Advisory
RHSA-2010:0755
  • Third Party Advisory
RHSA-2010:0859
  • Third Party Advisory
MDVSA-2010:231
  • Third Party Advisory
MDVSA-2010:228
  • Third Party Advisory
42357
  • Third Party Advisory
ADV-2010-3097
  • Third Party Advisory
SSA:2010-324-01
  • Third Party Advisory
42691
  • Third Party Advisory
DSA-2135
  • Third Party Advisory
SUSE-SR:2010:023
  • Mailing List
  • Third Party Advisory
SUSE-SR:2010:024
  • Mailing List
  • Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html
  • Third Party Advisory
ADV-2011-0230
  • Third Party Advisory
43079
  • Third Party Advisory
RHSA-2012:1201
  • Third Party Advisory
MDVSA-2012:144
  • Third Party Advisory
    1. Конфигурация 1

      cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
      Start including
      0.8.7
      End including
      0.15.1

      cpe:2.3:a:xpdfreader:xpdf:3.02:pl1:*:*:*:*:*:*

      cpe:2.3:a:xpdfreader:xpdf:3.02:pl2:*:*:*:*:*:*

      cpe:2.3:a:xpdfreader:xpdf:3.02:pl3:*:*:*:*:*:*

      cpe:2.3:a:xpdfreader:xpdf:3.02:pl4:*:*:*:*:*:*

      cpe:2.3:a:xpdfreader:xpdf:3.02:-:*:*:*:*:*:*

      cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*:*
      End including
      3.01

      cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*
      End including
      1.3.11

      Конфигурация 2

      cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*

      Конфигурация 3

      cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*

      cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*

      cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:-:*:*:*

      Конфигурация 4

      cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*

      Конфигурация 5

      cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*

      Конфигурация 6

      cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*