CVE-2010-3703: Input Validation

Published Oct 1, 2010
·
Updated

poppler git commit bf2055088a corrects a possible use of an uninitialized pointer in PostScriptFunction, which can cause crash or memory corruption.

Upstream git commit: http://cgit.freedesktop.org/poppler/poppler/commit/?id=bf2055088a3a2d3bb3d3c37d464954ec1a25771f

This problem does not affect xpdf or other applications embedding xpdf code. It only affects recent poppler versions, not before commit:

http://cgit.freedesktop.org/poppler/poppler/commit/?id=b1d4efb082ac3dadd7752a557e5aeb6651e17471

Reference: http://secunia.com/advisories/41596/

Other sources

The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.

Affected Software

35 affected components
Poppler Poppler=0.8.7
Poppler Poppler=0.9.0
Poppler Poppler=0.9.1
Poppler Poppler=0.9.2
Poppler Poppler=0.9.3
Poppler Poppler=0.10.0
Poppler Poppler=0.10.1
Poppler Poppler=0.10.2
Poppler Poppler=0.10.3
Poppler Poppler=0.10.4
Poppler Poppler=0.10.5
Poppler Poppler=0.10.6
Poppler Poppler=0.10.7
Poppler Poppler=0.11.0
Poppler Poppler=0.11.1
Poppler Poppler=0.11.2
Poppler Poppler=0.11.3
Poppler Poppler=0.12.0
Poppler Poppler=0.12.1
Poppler Poppler=0.12.2
Poppler Poppler=0.12.3
Poppler Poppler=0.12.4
Poppler Poppler=0.13.0
Poppler Poppler=0.13.1
Poppler Poppler=0.13.2
Poppler Poppler=0.13.3
Poppler Poppler=0.13.4
Poppler Poppler=0.14.0
Poppler Poppler=0.14.1
Poppler Poppler=0.14.2
Poppler Poppler=0.14.3
Poppler Poppler=0.14.4
Poppler Poppler=0.14.5
Poppler Poppler=0.15.0
Poppler Poppler=0.15.1

Event History

Oct 1, 2010
Data Sourced
02:30 PM
DescriptionSeverityAffected Software
Nov 5, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2010-3703?

CVE-2010-3703 is classified as a moderate severity vulnerability due to possible crashes or memory corruption.

2

How do I fix CVE-2010-3703?

To resolve CVE-2010-3703, update Poppler to a version that includes the fix from commit bf2055088a.

3

Which versions of Poppler are affected by CVE-2010-3703?

CVE-2010-3703 affects multiple Poppler versions, including 0.8.7 to 0.15.1, specifically those mentioned in the vulnerability details.

4

What type of vulnerability is CVE-2010-3703?

CVE-2010-3703 is a security vulnerability that relates to the possible use of an uninitialized pointer in the Poppler library.

5

Is there any exploit available for CVE-2010-3703?

There is no publicly known exploit for CVE-2010-3703, but the risk of crashes or memory corruption remains.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203