Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000083

Опубликовано: 13 июл. 2017
Источник: redhat
CVSS3: 7.1

Описание

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

It was found that evince did not properly sanitize the command line which is run to untar Comic Book Tar (CBT) files, thereby allowing command injection. A specially crafted CBT file, when opened by evince or evince-thumbnailer, could execute arbitrary commands in the context of the evince program.

Меры по смягчению последствий

  • Disabling evince-thumbnailer to render icons will reduce the attack surface (removing /usr/share/thumbnailers/evince.thumbnailer).
  • SELinux in enforcing mode partially restricts evince-thumbnailer

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5evinceNot affected
Red Hat Enterprise Linux 6evinceNot affected
Red Hat Enterprise Linux 7evinceFixedRHSA-2017:238801.08.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1468488evince: command injection via filename in tar-compressed comics archive

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

CVSS3: 7.8
nvd
около 8 лет назад

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

CVSS3: 7.8
debian
около 8 лет назад

backend/comics/comics-document.c (aka the comic book backend) in GNOME ...

suse-cvrf
почти 8 лет назад

Security update for evince

suse-cvrf
больше 8 лет назад

Security update for evince

7.1 High

CVSS3