Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian 7 DLA-1204-1 Critical: Evince Command Injection Threat

debian lts
Calendar Grey December 11, 2017
Dist Debian Esm H88
Enhance your network's protection with the recent evince upgrade for Debian 7 addressing command execution flaws.
It was discovered that there was an arbitrary command injection in the evince PDF viewer

Summary

A specially-crafted embedded DVI filename could be exploited to run
commands as the current user when "printing" to PDF.

For Debian 7 "Wheezy", this issue has been fixed in evince version
3.4.0-3.1+deb7u2.

We recommend that you upgrade your evince packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
critical
Lowest
Low
Medium
High
Critical

Package: evince
Version: 3.4.0-3.1+deb7u2
CVE ID: CVE-2017-1000159

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here