Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-46529

Опубликовано: 10 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is shell/ev-application.c:ev_spawn, which builds a command line from attacker-controlled PDF link-destination fields without applying g_shell_quote. The cmdline is then handed to g_app_info_create_from_commandline, which shell-parses it back into argv — splitting any embedded --gtk-module=PATH into a separate argv element. GTK then dlopen()s the path during init, running any __attribute__((constructor)) it finds. Versions 1...

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

questing

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

49~alpha-2ubuntu3
esm-apps/resolute

released

49~alpha-2ubuntu2.1
esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

released

42.3-0ubuntu3.2
noble

released

46.3.1-0ubuntu1.1
questing

released

48.1-3ubuntu2.1
resolute

released

49~alpha-2ubuntu2.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

needs-triage

upstream

released

48.4+dfsg-1

Показывать по

РелизСтатусПримечание
devel

not-affected

50.1-0ubuntu2
jammy

DNE

noble

DNE

questing

released

48.0-1ubuntu1.25.10.4
resolute

released

50.1-0ubuntu1.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 42%
0.00529
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1...

CVSS3: 7.8
nvd
около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26

CVSS3: 7.8
debian
около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE deskt ...

suse-cvrf
около 1 месяца назад

Security update for papers

suse-cvrf
2 месяца назад

Security update for evince

EPSS

Процентиль: 42%
0.00529
Низкий

7.8 High

CVSS3

Уязвимость CVE-2026-46529