vulnerability
Huawei EulerOS: CVE-2017-1000083: evince security update
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Sep 5, 2017 | Nov 30, 2017 | Apr 25, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Sep 5, 2017
Added
Nov 30, 2017
Modified
Apr 25, 2025
Description
It was found that evince did not properly sanitize the command line which is run to untar Comic Book Tar (CBT) files, thereby allowing command injection. A specially crafted CBT file, when opened by evince or evince-thumbnailer, could execute arbitrary commands in the context of the evince program.
Solutions
huawei-euleros-2_0_sp2-upgrade-evincehuawei-euleros-2_0_sp2-upgrade-evince-dvihuawei-euleros-2_0_sp2-upgrade-evince-libshuawei-euleros-2_0_sp2-upgrade-evince-nautilus
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.