CVE-2012-2142

NameCVE-2012-2142
DescriptionInsufficient sanitization of escape sequences in the error message
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
Debian Bugs487773

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)wheezy0.18.4-6vulnerable
wheezy (security)0.18.4-6+deb7u5vulnerable
jessie0.26.5-2+deb8u1fixed
jessie (security)0.26.5-2+deb8u4fixed
stretch (security), stretch0.48.0-2+deb9u2fixed
buster0.62.0-2fixed
sid0.63.0-2fixed
xpdf (PTS)wheezy3.03-10fixed
jessie3.03-17fixed
stretch3.04-4fixed
buster, sid3.04-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
popplersource(unstable)0.18.4-7unimportant487773
xpdfsource(unstable)(not affected)

Notes

- xpdf <not-affected> (uses poppler's Error.cc)
poppler upstream patch http://cgit.freedesktop.org/poppler/poppler/commit/?id=71bad47ed6a36d825b0d08992c8db56845c71e40

Search for package or bug name: Reporting problems