Input validation error in Okular - CVE-2020-9359

 

Input validation error in Okular - CVE-2020-9359

Published: March 13, 2020


Vulnerability identifier: #VU26077
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9359
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input when processing links in PDF files in Okular. A remote attacker can trick the victim into opening a specially crafted PDF file and execute certain application on the system.


Affected software

Okular
Gentoo Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
okular (Red Hat package)
okular (Alpine package)
analitza (Alpine package)
akonadi-calendar-tools (Alpine package)
okular

How to mitigate CVE-2020-9359

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

okular (Red Hat package) - update to 4.10.5-9.el7
okular (Alpine package) - addressed in versions 19.08.3-r1, 19.12.3-r1
analitza (Alpine package) - update to 19.12.3-r0
akonadi-calendar-tools (Alpine package) - update to 20.04.0-r0
okular - addressed in versions 18.12.2-2.el8, 19.12.3-2.fc30, 19.12.3-2.fc31, 19.12.3-2.fc32

External References

Related Security Bulletins