Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
George Karagiannidis discovered multiple security vulnerabilities in the fax backend of the Okular document viewer, which could potentially result in the execution of arbitrary code if a malformed G3/G4 Fax file is opened. For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6332-1
An update for okular is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: okular security update Advisory ID: RHSA-2020:4024-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4024 Issue date: 2020-09-29 CVE Names: CVE-2020-9359 ==================================================================== 1. Summary: An update for okular is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: Okular is a universal document viewer developed by KDE supporting different kinds of documents, like PDF, Postscript, DjVu, CHM, XPS, ePub and others. Security Fix(es): * okular: local binary execution via specially crafted PDF files (CVE-2020-9359) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section. 4. Solution: Fordetails on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1815651 - CVE-2020-9359 okular: local binary execution via specially crafted PDF files 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: okular-4.10.5-9.el7.src.rpm x86_64: okular-4.10.5-9.el7.x86_64.rpm okular-debuginfo-4.10.5-9.el7.i686.rpm okular-debuginfo-4.10.5-9.el7.x86_64.rpm okular-libs-4.10.5-9.el7.i686.rpm okular-libs-4.10.5-9.el7.x86_64.rpm okular-part-4.10.5-9.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: okular-debuginfo-4.10.5-9.el7.i686.rpm okular-debuginfo-4.10.5-9.el7.x86_64.rpm okular-devel-4.10.5-9.el7.i686.rpm okular-devel-4.10.5-9.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: okular-4.10.5-9.el7.src.rpm ppc64le: okular-4.10.5-9.el7.ppc64le.rpm okular-debuginfo-4.10.5-9.el7.ppc64le.rpm okular-devel-4.10.5-9.el7.ppc64le.rpm okular-libs-4.10.5-9.el7.ppc64le.rpm okular-part-4.10.5-9.el7.ppc64le.rpm x86_64: okular-4.10.5-9.el7.x86_64.rpm okular-debuginfo-4.10.5-9.el7.i686.rpm okular-debuginfo-4.10.5-9.el7.x86_64.rpm okular-devel-4.10.5-9.el7.i686.rpm okular-devel-4.10.5-9.el7.x86_64.rpm okular-libs-4.10.5-9.el7.i686.rpm okular-libs-4.10.5-9.el7.x86_64.rpm okular-part-4.10.5-9.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: okular-4.10.5-9.el7.src.rpm x86_64: okular-4.10.5-9.el7.x86_64.rpm okular-debuginfo-4.10.5-9.el7.i686.rpm okular-debuginfo-4.10.5-9.el7.x86_64.rpm okular-devel-4.10.5-9.el7.i686.rpm okular-devel-4.10.5-9.el7.x86_64.rpm okular-libs-4.10.5-9.el7.i686.rpm okular-libs-4.10.5-9.el7.x86_64.rpm okular-part-4.10.5-9.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2020-9359 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX3OgeNzjgjWX9erEAQg88A//RVUXNMbVYSAOxgp1nM8YzzqUmMXM8C4P SKCEgpsw8nYhUKYJKLySZkfSAApk2IXf6tA7b7UkO6CzDvwjhU9OEoXneJo2GXO3 /QPpBCcLfKJ2Mz01PhY7m/ZDOcl7h+Nz3N89k5Ys+KXnUfB0B/cCye5OdhHZk+bM gxDbfew2fOG5QTMUMvSwF0DNhkHhukboqlUjvKE6YTkJSqv7EgccfQyI9kaTjeWp GQUGTkv6nwAx43AtiYI/dMfpJX0lQaEbsicpKTsbmahpyXYIXkbeZWd7bsQJcG/d ttEN1T5i+++uUJv/nCaUux6TBsiKuqOigIMyPdsj2IQeT6PmDl+Ir+PAPpRhOFkh roO9XRUHI71DUJCz9oU4ANlKI9CxzlJgy5ekH7ufHCSWbkGqC7torD6rLBah3NqQ AWKx+0Y7NlFVZ8+7v2XplxpYZ7pEE5psBo3erv5+MS15mvL7rq37Q4M40rV7qPAA 2P04p7yoT9FIP5pPZSUhywDaRxKMoJhVRWaEeUz6BhewuDGvi9murSwa3JzeqzRh GLEp2pnhaetVCg2IqhhbW1UWqnoQMOPvx1JMNMMkdOoVF9oOqWJacAWaQhALyM13 4pEyd3GAmlyixqUI1duHBU5rhAAlgiNFpJnCiI3MZpBmlLSP1yGQpML9EaI6Jq6+ RXEXr6QrRzo=Ck++ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
okular: Directory traversal in function unpackDocumentArchive() in core/document.cpp SL7 x86_64 okular-part-4.10.5-8.el7.x86_64.rpm okular-devel-4.10.5-8.el7.i686.rpm okular-libs-4.10.5-8.el7.x86_64.rpm okular-libs-4.10.5-8.el7.i686.rpm okular-devel-4.10.5-8.el7.x86_64.rpm okular-4.10.5-8.el7.x86_64.rpm okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debugin [More...]. Synopsis: Moderate: okular security update Advisory ID: SLSA-2020:1173-1 Issue Date: 2020-04-07 CVE Numbers: CVE-2018-1000801 -- * okular: Directory traversal in function unpackDocumentArchive() in core/document.cpp -- SL7 x86_64 okular-part-4.10.5-8.el7.x86_64.rpm okular-devel-4.10.5-8.el7.i686.rpm okular-libs-4.10.5-8.el7.x86_64.rpm okular-libs-4.10.5-8.el7.i686.rpm okular-devel-4.10.5-8.el7.x86_64.rpm okular-4.10.5-8.el7.x86_64.rpm okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debuginfo-4.10.5-8.el7.x86_64.rpm - Scientific Linux Development Team . Notification regarding Okular resolving medium risk path traversal vulnerability. Installation necessary for protection.. okular security, directory traversal, SL7 updates, Linux security, software vulnerabilities. . LinuxSecurity.com Team
An update for okular is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: okular security update Advisory ID: RHSA-2020:1173-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1173 Issue date: 2020-03-31 CVE Names: CVE-2018-1000801 ==================================================================== 1. Summary: An update for okular is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: Okular is a universal document viewer developed by KDE supporting different kinds of documents, like PDF, Postscript, DjVu, CHM, XPS, ePub and others. Security Fix(es): * okular: Directory traversal in function unpackDocumentArchive() in core/document.cpp (CVE-2018-1000801) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the Referencessection. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1626265 - CVE-2018-1000801 okular: Directory traversal in function unpackDocumentArchive() in core/document.cpp 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: okular-4.10.5-8.el7.src.rpm x86_64: okular-4.10.5-8.el7.x86_64.rpm okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debuginfo-4.10.5-8.el7.x86_64.rpm okular-libs-4.10.5-8.el7.i686.rpm okular-libs-4.10.5-8.el7.x86_64.rpm okular-part-4.10.5-8.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debuginfo-4.10.5-8.el7.x86_64.rpm okular-devel-4.10.5-8.el7.i686.rpm okular-devel-4.10.5-8.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: okular-4.10.5-8.el7.src.rpm ppc64le: okular-4.10.5-8.el7.ppc64le.rpm okular-debuginfo-4.10.5-8.el7.ppc64le.rpm okular-devel-4.10.5-8.el7.ppc64le.rpm okular-libs-4.10.5-8.el7.ppc64le.rpm okular-part-4.10.5-8.el7.ppc64le.rpm x86_64: okular-4.10.5-8.el7.x86_64.rpm okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debuginfo-4.10.5-8.el7.x86_64.rpm okular-devel-4.10.5-8.el7.i686.rpm okular-devel-4.10.5-8.el7.x86_64.rpm okular-libs-4.10.5-8.el7.i686.rpm okular-libs-4.10.5-8.el7.x86_64.rpm okular-part-4.10.5-8.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: okular-4.10.5-8.el7.src.rpm x86_64: okular-4.10.5-8.el7.x86_64.rpm okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debuginfo-4.10.5-8.el7.x86_64.rpm okular-devel-4.10.5-8.el7.i686.rpm okular-devel-4.10.5-8.el7.x86_64.rpm okular-libs-4.10.5-8.el7.i686.rpm okular-libs-4.10.5-8.el7.x86_64.rpm okular-part-4.10.5-8.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2018-1000801 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/7.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXoOcgNzjgjWX9erEAQjoAQ//du1ZkuKyr3fPdqg1TevacRXEcfdXEQ5T Z3wm+blxkNcDb1+jZ7xIXASwMwWZm7rtXGI01YVuTZObzRYc9zCHFytG7Ij/F7C4 M/K4EwDCvoPFxQVuoRzuRB5rwJ+nYwiM2UAFfEd0/jYE44iWadaOn4zYToiH9PqW /JgS2tQZl8ssBP/sG7E4pcmmFOK3084HMerb3bFr5SsqrfnYlXgCdKDecozBpP7S dOqGPC0wthQk/j0cY5+WJOWiwIpBozQt9pZStvl912ZU3Uq4Md464P80IHHP42uh pF4/M6C7wegAJ9ipncnZfAdGC/Jn0vE2X8SlpisyjjVvzLugq9tJBt2yiuFq36eK YEhBT+qSMahs+IZg5GNF+qe1J3C+nuwQVZciIX2E/5QTE+bCN6Y9uFqoZ2X+7WkN dzu8Qm5tSmPuEzo2czGfNhSgX3tudjcW8sQkXTGiGGQHTOmBPy/3G7CCVSkbM7hu ERbHxkA8LYbt8z/sTYkqAKBi5gjfKCmSdQUQ/u/IdDQI69Ij7e+rB5sX7ZKMtVYR U+5QfR0GyBsNSYCdbJ5hd2+1f9OYzdR5BcvMd97Lh61VGu1pL9md70umowYnBUTY IEwJqIBpCen5sL3y17ascfXq/ViahZsaOknai2N4WZfnL8h5aNgK8YtRVv3z5+z2 XskXuDj8u+k=69H3 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2020-9359. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e35573f7df 2020-03-31 01:23:26.927492 --------------------------------------------------------------------------------Name : okular Product : Fedora 30 Version : 19.12.3 Release : 2.fc30 URL : https://apps.kde.org//graphics/okular/ Summary : A document viewer Description : A document viewer. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2020-9359 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 22 2020 Rex Dieter - 19.12.3-2 - Security fix for CVE-2020-9359 (#1815651,1815652) * Fri Mar 6 2020 Rex Dieter - 19.12.3-1 - 19.12.3 * Tue Feb 4 2020 Rex Dieter - 19.12.2-1 - 19.12.2 * Thu Jan 30 2020 Rex Dieter - 19.12.1-1 - 19.12.1 * Wed Jan 29 2020 Fedora Release Engineering - 19.08.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Fri Jan 17 2020 Marek Kasik - 19.08.3-2 - Rebuild for poppler-0.84.0 * Tue Nov 12 2019 Rex Dieter - 19.08.3-1 - 19.08.3 * Thu Oct 17 2019 Rex Dieter - 19.08.2-1 - 19.08.2 * Mon Sep 30 2019 Rex Dieter - 19.08.1-1 - 19.08.1 * Thu Jul 25 2019 Fedora Release Engineering - 19.04.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri Jul 12 2019 Rex Dieter - 19.04.3-1 - 19.04.3 * Tue Jun 4 2019 Rex Dieter - 19.04.2-1 - 19.04.2 * Fri Mar 8 2019 Rex Dieter - 18.12.3-1 - 18.12.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1815651 - CVE-2020-9359 okular: local binary execution via specially crafted PDF files https://bugzilla.redhat.com/show_bug.cgi?id=1815651 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2020-e35573f7df' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Mickael Karatekin from Sysdream Labs discovered that the Okular document viewer allows code execution via an action link in a PDF document. . Package : okular Version : 4:4.14.2-2+deb8u2 CVE ID : CVE-2020-9359 Debian Bug : 954891 Mickael Karatekin from Sysdream Labs discovered that the Okular document viewer allows code execution via an action link in a PDF document. For Debian 8 "Jessie", this problem has been fixed in version 4:4.14.2-2+deb8u2. We recommend that you upgrade your okular packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance Okular to address a vulnerability in code execution flagged by Mickael Karatekin in Debian 8.. Debian LTS, Okular Update, Security Patch. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2020-9359. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-7036f54316 2020-03-24 01:48:02.704940 --------------------------------------------------------------------------------Name : okular Product : Fedora 31 Version : 19.12.3 Release : 2.fc31 URL : https://apps.kde.org//graphics/okular/ Summary : A document viewer Description : A document viewer. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2020-9359 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 22 2020 Rex Dieter - 19.12.3-2 - Security fix for CVE-2020-9359 (#1815651,1815652) * Fri Mar 6 2020 Rex Dieter - 19.12.3-1 - 19.12.3 * Tue Feb 4 2020 Rex Dieter - 19.12.2-1 - 19.12.2 * Thu Jan 30 2020 Rex Dieter - 19.12.1-1 - 19.12.1 * Wed Jan 29 2020 Fedora Release Engineering - 19.08.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Fri Jan 17 2020 Marek Kasik - 19.08.3-2 - Rebuild for poppler-0.84.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1815651 - CVE-2020-9359 okular: local binary execution via specially crafted PDF files https://bugzilla.redhat.com/show_bug.cgi?id=1815651 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-7036f54316' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated okular packages fix security vulnerability: Okular can be tricked into executing local binaries via specially crafted PDF files. This binary execution can require almost no user interaction. No parameters can be passed to those local binaries (CVE-2020-9359). . MGASA-2020-0145 - Updated okular packages fix security vulnerability Publication date: 18 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0145.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-9359 Updated okular packages fix security vulnerability: Okular can be tricked into executing local binaries via specially crafted PDF files. This binary execution can require almost no user interaction. No parameters can be passed to those local binaries (CVE-2020-9359). References: - https://bugs.mageia.org/show_bug.cgi?id=26342 - https://kde.org/info/security/advisory-20200312-1.txt - https://www.cve.org/CVERecord?id=CVE-2020-9359 SRPMS: - 7/core/okular-19.04.0-1.1.mga7 . Revised Okular distributions address a vulnerability related to local binary execution via specially crafted PDF documents requiring only slight user interaction.. Okular Security Update, Mageia Security Advisory, Local Binary Execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.