Back

HIGH

evince: command injection via filename in tar-compressed comics archive

Published Sep 5, 2017

Description

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

Affected products

Remediation

Red Hat mitigation

- Disabling evince-thumbnailer to render icons will reduce the attack surface (removing /usr/share/thumbnailers/evince.thumbnailer). - SELinux in enforcing mode partially restricts evince-thumbnailer

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 5, 2017
Updated Aug 5, 2024
Reserved Jul 13, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 13, 2017