CVE-2012-2142
HIGHpoppler <0.21.4 - RCE
Title source: llmDescription
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
References (6)
Scores
CVSS v3
7.8
EPSS
0.0133
EPSS Percentile
79.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
Status
published
Affected Products (5)
freedesktop/poppler
< 0.21.4
xpdfreader/xpdf
redhat/enterprise_linux
redhat/enterprise_linux
opensuse/opensuse
Timeline
Published
Jan 09, 2020
Tracked Since
Feb 18, 2026