Code injection in Evince - CVE-2017-1000083

 

Code injection in Evince - CVE-2017-1000083

Published: July 14, 2017 / Updated: June 17, 2021


Vulnerability identifier: #VU7546
CSH Severity: High
CVSS v4 BT: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]
CVE-ID: CVE-2017-1000083
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to insufficient sanitization of user-supplied data when processing tar comic book (cbt) files in evince. A remote attacker can create a speicially crafted "cbt" file, trick the victim into downloading it and execute arbitrary commands on vulnerable system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Affected software

Evince
Arch Linux
Debian Linux
Red Hat Enterprise Linux Server
SUSE Linux
Ubuntu
Fedora
Opensuse
evince (Alpine package)
evince

How to mitigate CVE-2017-1000083

Update to version 3.25.0.

evince (Alpine package) - addressed in versions 3.24.0-r2, 3.24.1-r0
evince - addressed in versions 3.20.1-3.fc24, 3.22.1-5.fc25, 3.24.0-3.fc26

External References

Related Security Bulletins