Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3703
HistoryOct 13, 2010 - 12:00 a.m.

CVE-2010-3703

2010-10-1300:00:00
ubuntu.com
ubuntu.com
15

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.011

Percentile

84.4%

The PostScriptFunction::PostScriptFunction function in poppler/Function.cc
in the PDF parser in poppler 0.8.7 and possibly other versions up to
0.15.1, and possibly other products, allows context-dependent attackers to
cause a denial of service (crash) via a PDF file that triggers an
uninitialized pointer dereference.

Bugs

Notes

Author Note
mdeslaur only affect poppler versions after b1d4efb082

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.011

Percentile

84.4%