First published: Fri Jul 07 2017(Updated: )
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Evince | <=3.24.0 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000083 is rated as high severity due to its ability to allow remote code execution.
To fix CVE-2017-1000083, update GNOME Evince to version 3.24.1 or later.
CVE-2017-1000083 affects GNOME Evince versions prior to 3.24.1 and several versions of Debian and Red Hat Enterprise Linux.
Yes, CVE-2017-1000083 can be exploited remotely through specially crafted .cbt files.
CVE-2017-1000083 is a remote code execution vulnerability that affects GNOME Evince.