LWN.net Logo

poppler: arbitrary command execution

Package(s):poppler CVE #(s):CVE-2010-4653
Created:February 14, 2011 Updated:February 16, 2011
Description: From the Pardus advisory:

Due to an integer overflow when parsing CharCodes for fonts and a failure to check the return value of a memory allocation, it is possible to trigger writes to a narrow range of offsets from a NULL pointer.

Alerts:
Pardus 2011-44 2011-02-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds