Vulnerability Report

CVE-2010-3702

Title: Xpdfreader Xpdf Memory Corruption

Memory Corruption

Proof Of Concept

No public PoC currently indexed for CVE-2010-3702.

CWE Category CWE-476
Published Date Nov 05, 2010
Modified Date Apr 29, 2026
Exploit Status Not Found
Score 7.5 CVSS v2.0
Exploit Probability (EPSS)
7.63%

Vulnerability Summary

CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.

Impacted Vendors

Reference Links

ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patch http://cgit.freedesktop.org/poppler/poppler/commit/?id=e853106b58d6b4b0467dbd6436c9bb1cfbd372cf http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.html http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html http://rhn.redhat.com/errata/RHSA-2012-1201.html http://secunia.com/advisories/42141 http://secunia.com/advisories/42357 http://secunia.com/advisories/42397 http://secunia.com/advisories/42691 http://secunia.com/advisories/43079 http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720 http://www.debian.org/security/2010/dsa-2119 http://www.debian.org/security/2010/dsa-2135 http://www.mandriva.com/security/advisories?name=MDVSA-2010:228 http://www.mandriva.com/security/advisories?name=MDVSA-2010:229 http://www.mandriva.com/security/advisories?name=MDVSA-2010:230 http://www.mandriva.com/security/advisories?name=MDVSA-2010:231 http://www.mandriva.com/security/advisories?name=MDVSA-2012:144 http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html http://www.openwall.com/lists/oss-security/2010/10/04/6 http://www.redhat.com/support/errata/RHSA-2010-0749.html http://www.redhat.com/support/errata/RHSA-2010-0750.html http://www.redhat.com/support/errata/RHSA-2010-0751.html http://www.redhat.com/support/errata/RHSA-2010-0752.html http://www.redhat.com/support/errata/RHSA-2010-0753.html http://www.redhat.com/support/errata/RHSA-2010-0754.html http://www.redhat.com/support/errata/RHSA-2010-0755.html http://www.redhat.com/support/errata/RHSA-2010-0859.html http://www.securityfocus.com/bid/43845 http://www.ubuntu.com/usn/USN-1005-1 http://www.vupen.com/english/advisories/2010/2897 http://www.vupen.com/english/advisories/2010/3097 http://www.vupen.com/english/advisories/2011/0230 https://bugzilla.redhat.com/show_bug.cgi?id=595245 ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patch http://cgit.freedesktop.org/poppler/poppler/commit/?id=e853106b58d6b4b0467dbd6436c9bb1cfbd372cf http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.html http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html http://rhn.redhat.com/errata/RHSA-2012-1201.html http://secunia.com/advisories/42141 http://secunia.com/advisories/42357 http://secunia.com/advisories/42397 http://secunia.com/advisories/42691 http://secunia.com/advisories/43079 http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720 http://www.debian.org/security/2010/dsa-2119 http://www.debian.org/security/2010/dsa-2135 http://www.mandriva.com/security/advisories?name=MDVSA-2010:228 http://www.mandriva.com/security/advisories?name=MDVSA-2010:229 http://www.mandriva.com/security/advisories?name=MDVSA-2010:230 http://www.mandriva.com/security/advisories?name=MDVSA-2010:231 http://www.mandriva.com/security/advisories?name=MDVSA-2012:144 http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html http://www.openwall.com/lists/oss-security/2010/10/04/6 http://www.redhat.com/support/errata/RHSA-2010-0749.html http://www.redhat.com/support/errata/RHSA-2010-0750.html http://www.redhat.com/support/errata/RHSA-2010-0751.html http://www.redhat.com/support/errata/RHSA-2010-0752.html http://www.redhat.com/support/errata/RHSA-2010-0753.html http://www.redhat.com/support/errata/RHSA-2010-0754.html http://www.redhat.com/support/errata/RHSA-2010-0755.html http://www.redhat.com/support/errata/RHSA-2010-0859.html http://www.securityfocus.com/bid/43845 http://www.ubuntu.com/usn/USN-1005-1 http://www.vupen.com/english/advisories/2010/2897 http://www.vupen.com/english/advisories/2010/3097 http://www.vupen.com/english/advisories/2011/0230 https://bugzilla.redhat.com/show_bug.cgi?id=595245
CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2010-3702 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.