SB2020031151 - Input validation error in akonadi-calendar-tools (Alpine package)
Published: March 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-9359)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when processing links in PDF files in Okular. A remote attacker can trick the victim into opening a specially crafted PDF file and execute certain application on the system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=864c859e9deeda2c68e8310550ca3c6d70a28dd7
- https://git.alpinelinux.org/aports/commit/?id=9abb0848a3fcf1f3d93a73c700bfda9c438f1091
- https://git.alpinelinux.org/aports/commit/?id=de20df90c0f698d54f97fc2db8ca3b71562e9f77
- https://git.alpinelinux.org/aports/commit/?id=6253a98c558a2be7f91db6f2582b52cd6a0fcbf0
- https://git.alpinelinux.org/aports/commit/?id=dc9617ecddac979239dbd1743e70a81743f77f62