[Security] xpdf - CVE-2010-3702,3704
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
xpdf (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Karmic |
Fix Released
|
Medium
|
Unassigned | ||
Lucid |
Fix Released
|
Medium
|
Unassigned | ||
Maverick |
Fix Released
|
Medium
|
Unassigned | ||
Natty |
Fix Released
|
Medium
|
Unassigned |
Bug Description
Binary package hint: xpdf
CVE-2010-3702:
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler
0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and
possibly other products allows context-dependent attackers to cause a
denial of service (crash) via unknown vectors that trigger an uninitialized
pointer dereference.
CVE-2010-3704:
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in
xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to
0.15.1, kdegraphics, and possibly other products allows context-dependent
attackers to cause a denial of service (crash) and possibly execute
arbitrary code via a PDF file with a crafted Type1 font that contains a
negative array index, which bypasses input validation and which triggers
memory corruption.
visibility: | private → public |
Changed in xpdf (Ubuntu): | |
status: | New → Confirmed |
importance: | Undecided → Medium |
Note that despite the description, our kdegraphics packages aren't directly
affected as they use the system xpdf and not an embedded copy (like upstream
did).