CVE-2010-0207: Medium severity Xpdfreader Xpdf vulnerability
Published Oct 30, 2019
·Updated
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
Affected Software
8 affected componentsFixes available
Xpdfreader Xpdf=3.03-17
Debian Debian Linux=8.0
Xpdfreader Xpdf=3.04-4
Debian Debian Linux=9.0
Xpdfreader Xpdf=3.04-13
Debian Debian Linux=10.0
debian/poppler
20.09.0-3.1+deb11u120.09.0-3.1+deb11u222.12.0-2+deb12u125.03.0-5+deb13u225.03.0-11.1
debian/xpdf<=3.04+git20210103-3, <=3.04+git20220601-1, <=3.04+git20250304-1
Event History
Oct 30, 2019
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionWeakness
Data Sourced
09:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 17, 2026
Data Sourced
via Debian·09:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2010-0207?
CVE-2010-0207 is a vulnerability in xpdf that allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
2
How severe is CVE-2010-0207?
CVE-2010-0207 has a severity rating of 5.5 (medium).
3
Which software is affected by CVE-2010-0207?
The affected software includes poppler and xpdf packages on Debian.
4
How can the CVE-2010-0207 vulnerability be fixed?
To fix the CVE-2010-0207 vulnerability, update the poppler package to version 0.71.0-5 or later, or the xpdf package to version 3.04+git20220601-1 or later.
5
Where can I find more information about CVE-2010-0207?
You can find more information about CVE-2010-0207 on the Debian Security Tracker, Red Hat Bugzilla, and FreeDesktop Bugzilla.