MGASA-2017-0244

Source
https://advisories.mageia.org/MGASA-2017-0244.html
Import Source
https://advisories.mageia.org/MGASA-2017-0244.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0244
Related
Published
2017-08-05T19:19:47Z
Modified
2017-08-05T19:06:19Z
Summary
Updated evince packages fix security vulnerability
Details

Felix Wilhelm discovered that Evince did not safely invoke tar when handling tar comic book (cbt) files. An attacker could use this to construct a malicious cbt comic book format file that, when opened in Evince, executes arbitrary code. Please note that this update disables support for cbt files in Evince (CVE-2017-1000083).

References
Credits

Affected packages

Mageia:5 / evince

Package

Name
evince
Purl
pkg:rpm/mageia/evince?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.14.2-1.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / evince

Package

Name
evince
Purl
pkg:rpm/mageia/evince?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.24.1-1.mga6

Ecosystem specific

{
    "section": "core"
}