Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-46529

около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1...

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-46529

около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1...

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-46529

около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-46529

около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE deskt ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21106-1

около 1 месяца назад

Security update for papers

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20850-1

2 месяца назад

Security update for evince

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2288-1

около 2 месяцев назад

Security update for evince

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2235-1

около 2 месяцев назад

Security update for evince

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2232-1

около 2 месяцев назад

Security update for evince

EPSS: Низкий
rocky логотип

RLSA-2026:28998

около 1 месяца назад

Important: evince security update

EPSS: Низкий
rocky логотип

RLSA-2026:27819

около 1 месяца назад

Important: evince security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28998

около 1 месяца назад

ELSA-2026-28998: evince security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-27819

около 1 месяца назад

ELSA-2026-27819: evince security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1...

CVSS3: 7.8
1%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1...

CVSS3: 7.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26

CVSS3: 7.8
1%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE deskt ...

CVSS3: 7.8
1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21106-1

Security update for papers

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20850-1

Security update for evince

1%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2288-1

Security update for evince

1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2235-1

Security update for evince

1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2232-1

Security update for evince

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:28998

Important: evince security update

1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:27819

Important: evince security update

1%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-28998

ELSA-2026-28998: evince security update (IMPORTANT)

1%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-27819

ELSA-2026-27819: evince security update (IMPORTANT)

1%
Низкий
около 1 месяца назад

Уязвимостей на страницу