CVE-2017-1000083

Advisory lineage Upstream: 0 Downstream: 12
Deferred
Published: 05 Sept 2017, 06:00
Last modified:05 Aug 2024, 21:53

Vulnerability Summary

Overall Risk (default)
high
57/100
CVSS Score
7.8 HIGH
v3.0 (nvd)
EPSS Score
76.67% CRITICAL
77% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

05 Sept 2017, 06:00
Published
Vulnerability first disclosed
05 Aug 2024, 21:53
Last Modified
Vulnerability information updated

Description

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

CVSS Metrics

  • v3.0HIGHScore: 7.8CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 76.67% Percentile: 99%

Affected Systems

  • debiandebian_linux

    8.0 | 9.0

  • gnomeevince

    ≤ 3.24.0

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_server

    7.0 | 7.4 | 7.5 | 7.6

  • redhatenterprise_linux_server_aus

    7.4 | 7.6

  • redhatenterprise_linux_server_eus

    7.4 | 7.5 | 7.6

  • redhatenterprise_linux_server_tus

    7.4 | 7.6

  • redhatenterprise_linux_workstation

    7.0

References (8)