vulnerability

Ubuntu: USN-3351-1 (CVE-2017-1000083): Evince vulnerability

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jul 13, 2017
Added
Dec 20, 2017
Modified
Apr 25, 2025

Description

Felix Wilhelm discovered that Evince did not safely invoke tar when
handling tar comic book (cbt) files. An attacker could use this to
construct a malicious cbt comic book format file that, when opened
in Evince, executes arbitrary code. Please note that this update
disables support for cbt files in Evince.

Solution(s)

ubuntu-upgrade-evinceubuntu-upgrade-evince-common
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.