ID:1560 - Exploit for Code injection in Evince - CVE-2017-1000083
Published: March 18, 2020
Evince
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to insufficient sanitization of user-supplied data when processing tar comic book (cbt) files in evince. A remote attacker can create a speicially crafted "cbt" file, trick the victim into downloading it and execute arbitrary commands on vulnerable system.