CVE-2010-4654

Priority
Medium
Description
Malformed commands may cause corruption of the internal stack used
to maintain graphics contexts, leading to potentially exploitable
memory corruption.
References
Notes
 jdstrand> xpdf in koffice is 2.0
 mdeslaur> first patch may change API/ABI
 mdeslaur> first patch is for protection, second patch actually fixes
 mdeslaur> particular issue. Second patch is included in Lucid's poppler,
 mdeslaur> so we're not affected.
Package
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 15.04 (Vivid Vervet):DNE
Ubuntu 15.10 (Wily Werewolf):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 15.04 (Vivid Vervet):needs-triage
Ubuntu 15.10 (Wily Werewolf):needs-triage
Package
Source: ipe (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 15.04 (Vivid Vervet):needs-triage
Ubuntu 15.10 (Wily Werewolf):needs-triage
Package
Source: xpdf (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 15.04 (Vivid Vervet):needs-triage
Ubuntu 15.10 (Wily Werewolf):needs-triage
Package
Upstream:released (0.14.3)
Ubuntu 12.04 LTS (Precise Pangolin):not-affected
Ubuntu 14.04 LTS (Trusty Tahr):not-affected
Ubuntu 15.04 (Vivid Vervet):not-affected
Ubuntu 15.10 (Wily Werewolf):not-affected
Patches:
Upstream:http://cgit.freedesktop.org/poppler/poppler/commit/?id=8284008aa8230a92ba08d547864353d3290e9bf9
Upstream:http://cgit.freedesktop.org/poppler/poppler/commit/?id=17345173
More Information

Valid XHTML 1.0 Strict

Updated: 2015-07-29 20:15:09 UTC (commit 9756)