Vulnerability Description
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freedesktop | Poppler | < 0.21.4 |
| Xpdfreader | Xpdf | 3.02 |
| Redhat | Enterprise Linux | 5.0 |
| Opensuse | Opensuse | 12.2 |
References
- http://cgit.freedesktop.org/poppler/poppler/commit/?id=71bad47ed6a36d825b0d08992PatchVendor Advisory
- http://cgit.freedesktop.org/poppler/poppler/commit/NEWS?id=2bc48d5369f1dbecfc4dbPatchVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00049.htmlMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/08/09/5ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/08/09/6ExploitMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=789936Issue TrackingThird Party Advisory
- http://cgit.freedesktop.org/poppler/poppler/commit/?id=71bad47ed6a36d825b0d08992PatchVendor Advisory
- http://cgit.freedesktop.org/poppler/poppler/commit/NEWS?id=2bc48d5369f1dbecfc4dbPatchVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00049.htmlMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/08/09/5ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/08/09/6ExploitMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=789936Issue TrackingThird Party Advisory
FAQ
What is CVE-2012-2142?
CVE-2012-2142 is a vulnerability with a CVSS score of 7.8 (HIGH). The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
How severe is CVE-2012-2142?
CVE-2012-2142 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2142?
Check the references section above for vendor advisories and patch information. Affected products include: Freedesktop Poppler, Xpdfreader Xpdf, Redhat Enterprise Linux, Opensuse Opensuse.