Red Hat Security Advisory 2017-2388-01

Discussion in 'News Aggregator' started by Packet Storm, 2 Aug 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-2388-01 - The evince packages provide a simple multi-page document viewer for Portable Document Format, PostScript, Encapsulated PostScript files, and, with additional back-ends, also the Device Independent File format files. Security Fix: It was found that evince did not properly sanitize the command line which is run to untar Comic Book Tar files, thereby allowing command injection. A specially crafted CBT file, when opened by evince or evince-thumbnailer, could execute arbitrary commands in the context of the evince program.

    Continue reading...
     

Share This Page

Loading...