CVE-2019-1010006: Integer Overflow
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiffdocumentrender and tiffdocumentgetthumbnail.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/atrilto a version that resolves this vulnerability.Fixed in 1.26.0-2+deb12u4Fixed in 1.26.2-4+deb13u1Fixed in 1.28.4-1 - Upgrade
Upgrade
debian/evinceto a version that resolves this vulnerability.Fixed in 43.1-2+deb12u1Fixed in 48.1-3+deb13u1Fixed in 49~alpha.1-2
Event History
Frequently Asked Questions
What is the vulnerability ID for Evince 3.26.0?
The vulnerability ID for Evince 3.26.0 is CVE-2019-1010006.
What is the impact of CVE-2019-1010006?
The impact of CVE-2019-1010006 is Denial of Service (DOS) and possible code execution.
Which component of Evince is affected by CVE-2019-1010006?
The component of Evince affected by CVE-2019-1010006 is backend/tiff/tiff-document.c.
What is the attack vector for CVE-2019-1010006?
The attack vector for CVE-2019-1010006 is the victim must open a crafted PDF file.
How can the buffer overflow vulnerability in Evince 3.26.0 be fixed?
To fix the buffer overflow vulnerability in Evince 3.26.0, update the software to version 3.18.2-1ubuntu4.6 or higher.