ZDI-CAN-30289: ZDI-26-360: MATE Desktop Atril Document Viewer EPUB File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MATE Desktop Atril Document Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-52849.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30289?
The severity of ZDI-CAN-30289 is rated at 77.
What type of vulnerability is ZDI-CAN-30289?
ZDI-CAN-30289 is a heap-based buffer overflow vulnerability in MATE Desktop Atril Document Viewer.
How does ZDI-CAN-30289 allow remote code execution?
ZDI-CAN-30289 allows remote code execution by exploiting a vulnerability that requires user interaction to open a malicious file or visit a malicious page.
What versions of MATE Atril Document Viewer are affected by ZDI-CAN-30289?
ZDI-CAN-30289 affects all installations of MATE Desktop Atril Document Viewer before security updates are applied.
How do I fix ZDI-CAN-30289?
To fix ZDI-CAN-30289, update MATE Desktop Atril Document Viewer to the latest version that addresses this vulnerability.