Access of Uninitialized Pointer in Evince - CVE-2019-11459
Published: June 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due tothe TIFFReadRGBAImageOriented() function called from tiff_document_render() and tiff_document_get_thumbnail() functions in the backend/tiff/tiff-document.c in GNOME Evince returns uninitialized memory instead of false, when failing to read an image. A remote attacker can gain access to sensitive information on the system.
Affected software
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Ubuntu
openEuler
Fedora
evince (Alpine package)
atril (Ubuntu package)
atril-common (Ubuntu package)
libatrildocument3 (Ubuntu package)
evince
gnome-remote-desktop (Red Hat package)
accountsservice (Red Hat package)
plymouth (Red Hat package)
poppler (Red Hat package)
SDL (Red Hat package)
wayland-protocols (Red Hat package)
gvfs (Red Hat package)
pango (Red Hat package)
gjs (Red Hat package)
pidgin (Red Hat package)
webkit2gtk3 (Red Hat package)
gdk-pixbuf2 (Red Hat package)
evince (Debian package)
gtk3 (Red Hat package)
baobab (Red Hat package)
file-roller (Red Hat package)
gnome-tweaks (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
evince (Red Hat package)
gdm (Red Hat package)
evince-help
evince-debuginfo
evince-devel
evince-debugsource
gnome-software (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-desktop3 (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
appstream-data (Red Hat package)
chrome-gnome-shell (Red Hat package)
mozjs60 (Red Hat package)
How to mitigate CVE-2019-11459
atril (Ubuntu package) - addressed in versions Ubuntu Pro, 1.24.0-1ubuntu0.2, 1.26.0-1ubuntu1.2
atril-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1.24.0-1ubuntu0.2, 1.26.0-1ubuntu1.2
libatrildocument3 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.24.0-1ubuntu0.2, 1.26.0-1ubuntu1.2
evince - addressed in versions master-3020190614123051.1, 3.30.2-4.fc29, 3.32.0-3.fc30
gnome-remote-desktop (Red Hat package) - update to 0.1.6-5.el8
accountsservice (Red Hat package) - update to 0.6.50-7.el8
plymouth (Red Hat package) - update to 0.9.3-15.el8
poppler (Red Hat package) - update to 0.26.5-42.el7
SDL (Red Hat package) - update to 1.2.15-35.el8
wayland-protocols (Red Hat package) - update to 1.17-1.el8
gvfs (Red Hat package) - update to 1.36.2-6.el8
pango (Red Hat package) - update to 1.42.4-6.el8
gjs (Red Hat package) - update to 1.56.2-3.el8
pidgin (Red Hat package) - update to 2.13.0-5.el8
webkit2gtk3 (Red Hat package) - update to 2.24.3-1.el8
gdk-pixbuf2 (Red Hat package) - update to 2.36.12-5.el8
evince (Debian package) - addressed in versions 3.22.1-3+deb9u2, 3.30.2-3+deb10u1
gtk3 (Red Hat package) - update to 3.22.30-4.el8
baobab (Red Hat package) - update to 3.28.0-2.el8
file-roller (Red Hat package) - update to 3.28.1-2.el8
gnome-tweaks (Red Hat package) - update to 3.28.1-6.el8
nautilus (Red Hat package) - update to 3.28.1-10.el8
gnome-control-center (Red Hat package) - update to 3.28.2-5.el8
evince (Red Hat package) - addressed in versions 3.28.2-9.el7, 3.28.4-3.el8
gdm (Red Hat package) - update to 3.28.3-22.el8
evince - update to 3.30.1-4
evince-help - update to 3.30.1-4
evince-debuginfo - update to 3.30.1-4
evince-devel - update to 3.30.1-4
evince-debugsource - update to 3.30.1-4
gnome-software (Red Hat package) - update to 3.30.6-2.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-3.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-4.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-10.el8
gnome-desktop3 (Red Hat package) - update to 3.32.2-1.el8
gnome-shell (Red Hat package) - update to 3.32.2-9.el8
mutter (Red Hat package) - update to 3.32.2-10.el8
appstream-data (Red Hat package) - update to 8-20190805.el8
chrome-gnome-shell (Red Hat package) - update to 10.1-6.el8
mozjs60 (Red Hat package) - update to 60.9.0-3.el8
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00089.html
- https://access.redhat.com/errata/RHSA-2019:3553
- https://gitlab.gnome.org/GNOME/evince/issues/1129
- https://lists.debian.org/debian-lts-announce/2019/08/msg00013.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LU4YZK5S46TZAH4J3NYYUYFMOC47LJG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJ6R7NMY44IHIQIY24CV3WV2GLGJPQPZ/
- https://seclists.org/bugtraq/2020/Feb/18
- https://usn.ubuntu.com/3959-1/
- https://www.debian.org/security/2020/dsa-4624
Related Security Bulletins
- Information disclosure in GNOME Evince
- Amazon Linux AMI update for poppler
- Access of Uninitialized Pointer in evince (Alpine package)
- Debian update for evince
- Red Hat Enterprise Linux 8 update for GNOME
- Red Hat Enterprise Linux 7 update for poppler and evince
- openEuler update for evince
- Ubuntu update for atril
- Fedora 30 update for evince
- Fedora 29 update for evince
- Fedora 30 Flatpaks update for evince