CVE-2008-2950
07.07.2008, 23:41
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.
| Vendor | Product | Version |
|---|---|---|
| poppler | poppler | 𝑥 ≤ 0.8.4 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| poppler |
| ||||||||||||
| xpdf |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gpdf |
| ||||||||||||||
| ipe |
| ||||||||||||||
| kdegraphics |
| ||||||||||||||
| koffice |
| ||||||||||||||
| libextractor |
| ||||||||||||||
| pdfkit.framework |
| ||||||||||||||
| pdftohtml |
| ||||||||||||||
| poppler |
| ||||||||||||||
| tetex-bin |
| ||||||||||||||
| texlive-bin |
| ||||||||||||||
| xpdf |
|
References