okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade okular-develUpgrade okularUpgrade okular-libsUpgrade okular-debuginfoUpgrade okular-part | Apr 1, 2020 | Sep 6, 2018 |
| Debian | — | Upgrade okular | Sep 25, 2018 | Sep 6, 2018 |
| Gentoo Linux | — | Upgrade kde-apps/okular. | Nov 12, 2018 | Sep 6, 2018 |
| Oracle_linux | — | Upgrade okularUpgrade okular-partUpgrade okular-develUpgrade okular-libs | Oct 5, 2022 | Sep 6, 2018 |
| Redhat_linux | — | Upgrade okular-libsUpgrade okular-debuginfoUpgrade okular-develUpgrade okularUpgrade okular-part | Apr 1, 2020 | Sep 6, 2018 |
| Suse | — | Upgrade okular-langUpgrade okular-develUpgrade okular | Sep 17, 2018 | Sep 6, 2018 |
| Ubuntu | — | Upgrade qml-module-org-kde-okular (Ubuntu Pro)Upgrade okular (Ubuntu Pro)Upgrade libokular5core8 (Ubuntu Pro) | Mar 22, 2023 | Sep 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub