vulnerability

Huawei EulerOS: CVE-2017-1000083: evince security update

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Sep 5, 2017
Added
Nov 30, 2017
Modified
Apr 25, 2025

Description

It was found that evince did not properly sanitize the command line which is run to untar Comic Book Tar (CBT) files, thereby allowing command injection. A specially crafted CBT file, when opened by evince or evince-thumbnailer, could execute arbitrary commands in the context of the evince program.

Solutions

huawei-euleros-2_0_sp2-upgrade-evincehuawei-euleros-2_0_sp2-upgrade-evince-dvihuawei-euleros-2_0_sp2-upgrade-evince-libshuawei-euleros-2_0_sp2-upgrade-evince-nautilus
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.