MEDIUM
poppler: heap based buffer overflow in DCTStream.cc
Published Aug 29, 2014
4.3
MEDIUMCVSS 2.0
EPSS 2.98%
Description
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
Affected products
No data.
OR
- ≤ 0.13.2
- 0.13.0
- 0.13.1
No data.
Red Hat Enterprise Linux 5
poppler
Will not fix
Red Hat Enterprise Linux 6
poppler
Will not fix
Red Hat Enterprise Linux 7
poppler
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | poppler | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | poppler | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | poppler | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- http://cgit.freedesktop.org/poppler/poppler/commit/poppler/DCTStream.cc?id=fc071d800cb4329a3ccf898d7bf16b4db7323ad8 x_refsource_CONFIRMExploitPatch
- http://comments.gmane.org/gmane.comp.security.oss.general/11132 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/59857 third-party-advisoryx_refsource_SECUNIA
- https://access.redhat.com/security/cve/CVE-2010-5110 Vendor Advisory
- https://bugs.freedesktop.org/show_bug.cgi?id=26280 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=647377 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-5110
- https://www.cve.org/CVERecord?id=CVE-2010-5110
- https://www.suse.com/support/update/announcement/2014/suse-su-20140817-1.html vendor-advisoryx_refsource_SUSE
| Link | Providers | Tags |
|---|---|---|
| http://cgit.freedesktop.org/poppler/poppler/commit/poppler/DCTStream.cc?id=fc071d800cb4329a3ccf898d7bf16b4db7323ad8 | x_refsource_CONFIRMExploitPatch | |
| http://comments.gmane.org/gmane.comp.security.oss.general/11132 | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/59857 | third-party-advisoryx_refsource_SECUNIA | |
| https://access.redhat.com/security/cve/CVE-2010-5110 | Vendor Advisory | |
| https://bugs.freedesktop.org/show_bug.cgi?id=26280 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=647377 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-5110 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-5110 | ||
| https://www.suse.com/support/update/announcement/2014/suse-su-20140817-1.html | vendor-advisoryx_refsource_SUSE |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 29, 2014
Updated Aug 7, 2024
Reserved Apr 30, 2012
Link CVE-2010-5110
CISA Vulnrichment
Updated n/a