ID:6149 - Exploit for Code injection in Evince - CVE-2017-1000083

 
Main Vulnerability Database Exploits ID:6149 - Exploit for Code injection in Evince - CVE-2017-1000083

ID:6149 - Exploit for Code injection in Evince - CVE-2017-1000083

Published: June 17, 2021


Vulnerability identifier: #VU7546
Vulnerability risk: High
CVE-ID: CVE-2017-1000083
CWE-ID: CWE-94
Exploitation vector: Remote access
Vulnerable software:
Evince

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to insufficient sanitization of user-supplied data when processing tar comic book (cbt) files in evince. A remote attacker can create a speicially crafted "cbt" file, trick the victim into downloading it and execute arbitrary commands on vulnerable system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Remediation

Update to version 3.25.0.