CVE-2012-2142: High severity poppler data vulnerability
An insufficient escape sequences sanitization flaw was found in the way xpdf, a PDF file viewer for the X window system, and poppler, a PDF rendering library, performed sanitization of certain characters to be displayed in the error messages, which arose during presentation of certain PDF files. A remote attacker could use this flaw to modify a window's title, or, possibly execute arbitrary commands or overwrite files, via a specially-crafted PDF file containing an escape sequence for a terminal emulator if local, unsuspecting user opened such crafted PDF file in xpdf or in an application linked against poppler library (for example evince).
Other sources
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2012-2142.
What is the severity of vulnerability CVE-2012-2142?
The severity of vulnerability CVE-2012-2142 is high with a severity value of 7.8.
Which software versions are affected by CVE-2012-2142?
The software versions affected by CVE-2012-2142 are poppler before 0.21.4, Xpdfreader 3.02, Redhat Enterprise Linux 5.0 and 6.0, and Opensuse 12.2.
How does CVE-2012-2142 allow remote attackers to execute arbitrary commands?
CVE-2012-2142 allows remote attackers to execute arbitrary commands by exploiting the escape sequence for a terminal emulator in a PDF.
How can I fix vulnerability CVE-2012-2142?
To fix vulnerability CVE-2012-2142, it is recommended to update to poppler version 0.21.4 or apply the relevant security patches from the respective vendor.