Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-1000083OS Command Injection in Evince

CWE-78OS Command Injection11 documents9 sources
Severity
7.8HIGHNVD
EPSS
76.7%
top 1.05%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedSep 5
Latest updateMay 13

Description

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Debiangnome/evince< 3.22.1-4+3
NVDgnome/evince3.24.0
Debianmate-desktop/atril< 1.16.1-2.1+3

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.4, 7.6, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c796-cmwx-5c79: backend/comics/comics-document2022-05-13
OSV
CVE-2017-1000083: backend/comics/comics-document2017-09-05
CVEList
CVE-2017-1000083: backend/comics/comics-document2017-09-05

💥Exploits & PoCs

2
Exploit-DB
Evince - CBT File Command Injection (Metasploit)2019-02-11
Exploit-DB
Evince 3.24.0 - Command Injection2018-11-13

📋Vendor Advisories

3
Ubuntu
Evince vulnerability2017-07-13
Red Hat
evince: command injection via filename in tar-compressed comics archive2017-07-13
Debian
CVE-2017-1000083: atril - backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince be...2017

💬Community

2
Bugzilla
CVE-2017-1000083 evince: command injection via filename in tar-compressed comics archive [fedora-all]2017-07-13
Bugzilla
CVE-2017-1000083 evince: command injection via filename in tar-compressed comics archive2017-07-07
CVE-2017-1000083 — OS Command Injection in Gnome Evince | cvebase