CVE-2017-1000159: OS Command Injection
Published Nov 27, 2017
·Updated
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
Affected Software
3 affected componentsFixes available
debian/atril
1.20.3-1+deb10u11.24.0-11.26.0-21.26.1-1
debian/evince
3.30.2-3+deb10u13.38.2-143.1-245.0-1
Gnome Evince<3.25.91
Remediation
Patch Available
Event History
Nov 27, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID for this command injection vulnerability is CVE-2017-1000159.
2
What software is affected by this vulnerability?
The evince software is affected by this command injection vulnerability.
3
What versions of evince are affected by this vulnerability?
Versions earlier than 3.25.91 of evince are affected by this vulnerability.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is 7.8 (high).
5
How can I fix this command injection vulnerability in evince?
To fix this vulnerability, update evince to version 3.25.91 or later.