CVE-2010-0206: Null Pointer Dereference
Published Oct 30, 2019
·Updated
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
Affected Software
8 affected componentsFixes available
Xpdfreader Xpdf=3.03-17
Debian Debian Linux=8.0
Xpdfreader Xpdf=3.04-4
Debian Debian Linux=9.0
Xpdfreader Xpdf=3.04-13
Debian Debian Linux=10.0
debian/poppler
20.09.0-3.1+deb11u120.09.0-3.1+deb11u222.12.0-2+deb12u125.03.0-5+deb13u225.03.0-11.1
debian/xpdf<=3.04+git20210103-3, <=3.04+git20220601-1, <=3.04+git20250304-1
Event History
Oct 30, 2019
CVE Published
via MITRE·08:10 PM
Data Sourced
via MITRE·08:10 PM
DescriptionWeakness
Data Sourced
09:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 17, 2026
Data Sourced
via Debian·09:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0206?
The severity of CVE-2010-0206 is medium with a severity value of 5.5.
2
How does CVE-2010-0206 affect xpdf?
CVE-2010-0206 allows remote attackers to cause a denial of service in xpdf.
3
What is the affected software for CVE-2010-0206?
The affected software for CVE-2010-0206 is xpdf and poppler.
4
How can I fix CVE-2010-0206?
To fix CVE-2010-0206, update to the recommended versions of xpdf and poppler.
5
Where can I find more information about CVE-2010-0206?
You can find more information about CVE-2010-0206 at the following references: [link1](https://security-tracker.debian.org/tracker/CVE-2010-0206), [link2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0206)