Vulnerability Name: | CVE-2012-2142 (CCN-174777) | ||||||||||||||||||||||||
Assigned: | 2012-04-04 | ||||||||||||||||||||||||
Published: | 2013-02-13 | ||||||||||||||||||||||||
Updated: | 2020-01-15 | ||||||||||||||||||||||||
Summary: | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||
References: | Source: MISC Type: Patch, Vendor Advisory http://cgit.freedesktop.org/poppler/poppler/commit/?id=71bad47ed6a36d825b0d08992c8db56845c71e40 Source: MISC Type: Patch, Vendor Advisory http://cgit.freedesktop.org/poppler/poppler/commit/NEWS?id=2bc48d5369f1dbecfc4db2878f33bdeb80d8d90f Source: MITRE Type: CNA CVE-2012-2142 Source: MISC Type: Mailing List, Patch, Third Party Advisory http://lists.opensuse.org/opensuse-updates/2013-08/msg00049.html Source: MISC Type: Exploit, Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2013/08/09/5 Source: MISC Type: Exploit, Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2013/08/09/6 Source: CCN Type: Red Hat Bugzilla Bug 789936 (CVE-2012-2142) - CVE-2012-2142 poppler, xpdf: Insufficient sanitization of escape sequences in the error messages Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=789936 Source: XF Type: UNKNOWN poppler-cve20122142-sec-bypass(174777) Source: CCN Type: Poppler Web site Poppler Source: CCN Type: XpdfReader Web site XpdfReader | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |