int(5506)

Boletines de Vulnerabilidades


Múltiples vulnerabilidades en "Poppler"

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Obtener acceso
Dificultad Experto
Requerimientos del atacante Acceso fisico

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado Poppler

Descripción

CVE-2010-3702: Se han descubierto dos vulnerabilidades en la librería "Poppler". La vulnerabilidad reside en la interpretación de archivos PDF en la libreria "Poppler".
Un atacante podría causar ejecución de código remoto mediante la apertura de un archivo PDF con formato incorrecto.

CVE-2010-3704: Se han descubierto dos vulnerabilidades en la librería "Poppler. La vulnerabilidad reside en la interpretación de archivos PDF en la libreria "Poppler".
Un atacante podría causar ejecución de código remoto mediante la apertura de un archivo PDF con formato incorrecto.

Solución



Actualización de software

Debian (DSA 2116-1)

Source archives:
http://security.debian.org/pool/updates/main/p/poppler/poppler_0.8.7.orig.tar.gz
http://security.debian.org/pool/updates/main/p/poppler/poppler_0.8.7-4.diff.gz
http://security.debian.org/pool/updates/main/p/poppler/poppler_0.8.7-4.dsc
alpha architecture (DEC Alpha)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_alpha.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_alpha.deb
amd64 architecture (AMD x86_64 (AMD64))
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_amd64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_amd64.deb
arm architecture (ARM)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_arm.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_arm.deb
armel architecture (ARM EABI)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_armel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_armel.deb
hppa architecture (HP PA RISC)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_hppa.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_hppa.deb
i386 architecture (Intel ia32)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_i386.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_i386.deb
ia64 architecture (Intel ia64)
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_ia64.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_ia64.deb
mips architecture (MIPS (Big Endian))
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_mips.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_mips.deb
mipsel architecture (MIPS (Little Endian))
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_mipsel.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_mipsel.deb
powerpc architecture (PowerPC)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_powerpc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_powerpc.deb
s390 architecture (IBM S/390)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_s390.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_s390.deb
sparc architecture (Sun SPARC/UltraSPARC)
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-3_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-dbg_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler3_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt2_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib-dev_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-dev_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt-dev_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-qt4-dev_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/poppler-utils_0.8.7-4_sparc.deb
http://security.debian.org/pool/updates/main/p/poppler/libpoppler-glib3_0.8.7-4_sparc.deb

Red Hat (RHSA-2010:0859-3)
Red Hat Enterprise Linux Desktop v.6
Red Hat Enterprise Linux Desktop Opcional v.6
Red Hat Enterprise Linux HPC Node v.6
Red Hat Enterprise Linux HPC Node Opcional v.6
Red Hat Enterprise Linux HPC Node v.6
Red Hat Enterprise Linux Servidor v.6
Red Hat Enterprise Linux Servidor Opcional v.6
Red Hat Enterprise Linux Workstation v.6
Red Hat Enterprise Linux Workstation Opcional v.6
https://rhn.redhat.com/

Identificadores estándar

Propiedad Valor
CVE CVE-2010-3702
CVE-2010-3704
BID

Recursos adicionales

Debian Security Advisory (DSA 2116-1)
http://lists.debian.org/debian-security-announce/2010/msg00169.html

Red Hat Security Advisory (RHSA- 2010:0859-03)
https://rhn.redhat.com/errata/RHSA-2010-0859.html

Debian Security Advisory (DSA-2135-1)
http://lists.debian.org/debian-security-announce/2010/msg00186.html

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2010-10-13
1.1 Aviso emitido por Red Hat (2010:0859-03) 2010-11-11
1.2 Aviso actualizado por Debian (DSA-2135-1) 2010-12-23

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT