vulnerability

Oracle Linux: CVE-2017-1000083: ELSA-2017-2388: evince security update (IMPORTANT)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jul 13, 2017
Added
Aug 9, 2017
Modified
Dec 3, 2025

Description

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
It was found that evince did not properly sanitize the command line which is run to untar Comic Book Tar (CBT) files, thereby allowing command injection. A specially crafted CBT file, when opened by evince or evince-thumbnailer, could execute arbitrary commands in the context of the evince program.

Solutions

oracle-linux-upgrade-evinceoracle-linux-upgrade-evince-browser-pluginoracle-linux-upgrade-evince-develoracle-linux-upgrade-evince-dvioracle-linux-upgrade-evince-libsoracle-linux-upgrade-evince-nautilus
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.