CVE Vulnerabilities

CVE-2010-0206

NULL Pointer Dereference

Published: Oct 30, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 N/A
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
XpdfXpdfreader3.03-17 (including)3.03-17 (including)
IpeUbuntudevel*
IpeUbuntuhardy*
IpeUbuntulucid*
IpeUbuntumaverick*
IpeUbuntunatty*
IpeUbuntuoneiric*
KdegraphicsUbuntuhardy*
KdegraphicsUbuntulucid*
KdegraphicsUbuntumaverick*
KdegraphicsUbuntunatty*
KdegraphicsUbuntuupstream*
KofficeUbuntuhardy*
LibextractorUbuntudevel*
LibextractorUbuntuhardy*
LibextractorUbuntulucid*
LibextractorUbuntumaverick*
LibextractorUbuntunatty*
LibextractorUbuntuoneiric*
PopplerUbuntudevel*
PopplerUbuntuhardy*
PopplerUbuntulucid*
PopplerUbuntumaverick*
PopplerUbuntunatty*
PopplerUbuntuoneiric*
XpdfUbuntudevel*
XpdfUbuntuhardy*
XpdfUbuntulucid*
XpdfUbuntumaverick*
XpdfUbuntunatty*
XpdfUbuntuoneiric*

Potential Mitigations

References