CVE-2010-2575

Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
kdekde_sc
4.3.0
kdekde_sc
4.3.1
kdekde_sc
4.3.2
kdekde_sc
4.3.3
kdekde_sc
4.3.4
kdekde_sc
4.3.5
kdekde_sc
4.4.0
kdekde_sc
4.4.1
kdekde_sc
4.4.2
kdekde_sc
4.4.3
kdekde_sc
4.4.4
kdekde_sc
4.4.5
kdekde_sc
4.5.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
okular
bullseye
4:20.12.3-2
fixed
lenny
not-affected
bookworm
4:22.12.3-1
fixed
sid
4:23.08.1-2
fixed
trixie
4:23.08.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kdegraphics
lucid
Fixed 4:4.4.2-0ubuntu1.1
released
karmic
Fixed 4:4.3.2-0ubuntu1.1
released
jaunty
Fixed 4:4.2.2-0ubuntu2.1
released
hardy
not-affected
dapper
not-affected
References