4.6
CVSSv2

CVE-2017-1000159

Published: 27/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome evince

Vendor Advisories

Evince could be made to run programs if it printed a specially crafted file ...
Several vulnerabilities were discovered in evince, a simple multi-page document viewer CVE-2017-1000159 Tobias Mueller reported that the DVI exporter in evince is susceptible to a command injection vulnerability via specially crafted filenames CVE-2019-11459 Andy Nguyen reported that the tiff_document_render() and tiff_docume ...
Command injection in evince via filename when printing to PDF This affects versions earlier than 32591 ...