ALASMATE-DESKTOP1.X-2024-006

Related Vulnerabilities: CVE-2023-52076  

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability. (CVE-2023-52076)

ALASMATE-DESKTOP1.X-2024-006


Amazon Linux 2 Security Advisory: ALASMATE-DESKTOP1.X-2024-006
Advisory Release Date: 2024-02-15 04:09 Pacific
Advisory Updated Date: 2024-02-19 17:57 Pacific
Severity: Important

Issue Overview:

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability. (CVE-2023-52076)


Affected Packages:

atril


Note:

This advisory is applicable to Amazon Linux 2 - Mate-desktop1.x Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update atril to update your system.

New Packages:
aarch64:
    atril-1.20.2-1.amzn2.0.5.aarch64
    atril-libs-1.20.2-1.amzn2.0.5.aarch64
    atril-devel-1.20.2-1.amzn2.0.5.aarch64
    atril-caja-1.20.2-1.amzn2.0.5.aarch64
    atril-thumbnailer-1.20.2-1.amzn2.0.5.aarch64
    atril-debuginfo-1.20.2-1.amzn2.0.5.aarch64

i686:
    atril-1.20.2-1.amzn2.0.5.i686
    atril-libs-1.20.2-1.amzn2.0.5.i686
    atril-devel-1.20.2-1.amzn2.0.5.i686
    atril-caja-1.20.2-1.amzn2.0.5.i686
    atril-thumbnailer-1.20.2-1.amzn2.0.5.i686
    atril-debuginfo-1.20.2-1.amzn2.0.5.i686

src:
    atril-1.20.2-1.amzn2.0.5.src

x86_64:
    atril-1.20.2-1.amzn2.0.5.x86_64
    atril-libs-1.20.2-1.amzn2.0.5.x86_64
    atril-devel-1.20.2-1.amzn2.0.5.x86_64
    atril-caja-1.20.2-1.amzn2.0.5.x86_64
    atril-thumbnailer-1.20.2-1.amzn2.0.5.x86_64
    atril-debuginfo-1.20.2-1.amzn2.0.5.x86_64