ID:6088 - Exploit for Code injection in Evince - CVE-2017-1000083
Published: June 17, 2021
Evince
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to insufficient sanitization of user-supplied data when processing tar comic book (cbt) files in evince. A remote attacker can create a speicially crafted "cbt" file, trick the victim into downloading it and execute arbitrary commands on vulnerable system.