CVE-2010-4654: Critical severity Freedesktop poppler vulnerability
Dan Rosenberg reported an issue in xpdf/poppler code base:
http://thread.gmane.org/gmane.comp.security.oss.general/4109
Malformed commands may cause corruption of the internal stack used to maintain graphics contexts, leading to potentially exploitable memory corruption.
Acknowledgements:
Red Hat would like to thank Dan Rosenberg for reporting this issue.
Other sources
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2010-4654?
CVE-2010-4654 is a vulnerability in poppler before version 0.16.3 that may cause corruption of the internal stack.
How severe is CVE-2010-4654?
CVE-2010-4654 has a severity rating of 7 (high).
Which software is affected by CVE-2010-4654?
The following software packages are affected by CVE-2010-4654: poppler versions 0.71.0-5, 0.71.0-5+deb10u1, 20.09.0-3.1+deb11u1, and 22.12.0-2; xpdf versions 3.04-13, 3.04+git20210103-3, and 3.04+git20220601-1; Debian Linux versions 8.0, 9.0, and 10.0.
How can I fix CVE-2010-4654 in poppler?
To fix CVE-2010-4654 in poppler, you should upgrade to version 0.16.3 or later.
Where can I find more information about CVE-2010-4654?
You can find more information about CVE-2010-4654 at the following references: [1] CVE-2010-4654 on CVE website, [2] CVE-2010-4654 on NIST NVD website, [3] Bugzilla Red Hat report, [4] Commit information on freedesktop.org.