backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince prior to 3.24.1 allows remote malicious users to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnome evince |
||
debian debian linux 8.0 |
||
debian debian linux 9.0 |
||
redhat enterprise linux server eus 7.6 |
||
redhat enterprise linux server eus 7.4 |
||
redhat enterprise linux server eus 7.5 |
||
redhat enterprise linux server aus 7.6 |
||
redhat enterprise linux workstation 7.0 |
||
redhat enterprise linux server tus 7.4 |
||
redhat enterprise linux server 7.5 |
||
redhat enterprise linux server 7.0 |
||
redhat enterprise linux desktop 7.0 |
||
redhat enterprise linux server tus 7.6 |
||
redhat enterprise linux server aus 7.4 |
||
redhat enterprise linux server 7.4 |
||
redhat enterprise linux server 7.6 |