CVE-2012-2142: Freedesktop Poppler

High severity, CVSS 7.8. EPSS: 2.9% chance of exploitation in the next 30 days.

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

Affected products

  • Freedesktop Poppler: before 0.21.4 (fixed in 0.21.4)
  • Opensuse Opensuse: version 12.2 only
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only
  • Xpdfreader Xpdf: version 3.02 only

Published 2020-01-09. Last modified 2026-06-16.