Code injection in Evince - CVE-2017-1000083
Published: July 14, 2017 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to insufficient sanitization of user-supplied data when processing tar comic book (cbt) files in evince. A remote attacker can create a speicially crafted "cbt" file, trick the victim into downloading it and execute arbitrary commands on vulnerable system.
Affected software
Arch Linux
Debian Linux
Red Hat Enterprise Linux Server
SUSE Linux
Ubuntu
Fedora
Opensuse
evince (Alpine package)
evince
How to mitigate CVE-2017-1000083
evince - addressed in versions 3.20.1-3.fc24, 3.22.1-5.fc25, 3.24.0-3.fc26
External References
Related Security Bulletins
- Arch Linux update for evince
- Ubuntu update for Evince
- Debian update for evince
- Red Hat update for Evince
- Debian update for atril
- openSUSE update for evince
- SUSE Linux update for evince
- OpenSUSE Linux update for evince
- SUSE Linux update for evince
- SUSE Linux update for evince
- SUSE Linux update for evince
- Code injection in evince (Alpine package)
- Fedora 25 update for evince
- Fedora 24 update for evince
- Fedora 26 update for evince