CVE-2012-2142

Published: September 1, 2020
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
HIGH
CVSS v3: 7.8

Status

DocFilters Release Package State Justification Comment
25.1 xpdf (4.05) Not Affected Code Not Reachable
24.4 xpdf (4.05) Not Affected Code Not Reachable
24.4.0 xpdf (4.05) Not Affected Code Not Reachable
24.3 xpdf (4.05) Not Affected Code Not Reachable
24.2.1 xpdf (4.05) Not Affected Code Not Reachable
24.2 xpdf (4.05) Not Affected Code Not Reachable
24.1 xpdf (3.02) Not Affected Code Not Reachable
23.3 xpdf (3.02) Not Affected Code Not Reachable
23.2.1 xpdf (3.02) Not Affected Code Not Reachable
23.2 xpdf (3.02) Not Affected Code Not Reachable
23.1 xpdf (3.02) Not Affected Code Not Reachable

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
7.8
Base Severity
HIGH
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Version
3.1

References