HIGH
evince: Command injection when exporting to PDF
Published Nov 27, 2017
7.8
HIGHCVSS 3.0
EPSS 1.41%
Description
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
evince
Not affected
Red Hat Enterprise Linux 6
evince
Will not fix
Red Hat Enterprise Linux 7
evince
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | evince | Not affected | n/a |
| Red Hat Enterprise Linux 6 | evince | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | evince | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of evince as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Weaknesses (2)
References (11)
- https://access.redhat.com/security/cve/CVE-2017-1000159 Vendor Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=784947 x_refsource_CONFIRMIssue TrackingPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1521210 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2017/12/msg00006.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/08/msg00013.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/08/msg00014.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000159
- https://seclists.org/bugtraq/2020/Feb/18 mailing-listx_refsource_BUGTRAQ
- https://security.gentoo.org/glsa/201804-15 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2017-1000159
- https://www.debian.org/security/2020/dsa-4624 vendor-advisoryx_refsource_DEBIAN
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-1000159 | Vendor Advisory | |
| https://bugzilla.gnome.org/show_bug.cgi?id=784947 | x_refsource_CONFIRMIssue TrackingPatch | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1521210 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2017/12/msg00006.html | mailing-listx_refsource_MLIST | |
| https://lists.debian.org/debian-lts-announce/2019/08/msg00013.html | mailing-listx_refsource_MLIST | |
| https://lists.debian.org/debian-lts-announce/2019/08/msg00014.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000159 | ||
| https://seclists.org/bugtraq/2020/Feb/18 | mailing-listx_refsource_BUGTRAQ | |
| https://security.gentoo.org/glsa/201804-15 | vendor-advisoryx_refsource_GENTOO | |
| https://www.cve.org/CVERecord?id=CVE-2017-1000159 | ||
| https://www.debian.org/security/2020/dsa-4624 | vendor-advisoryx_refsource_DEBIAN |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 27, 2017
Updated Aug 5, 2024
Reserved Nov 27, 2017
Link CVE-2017-1000159
CISA Vulnrichment
Updated n/a