CVE-2017-1000159OS Command Injection in Evince

Severity
7.8HIGHNVD
EPSS
0.4%
top 41.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateMay 13

Description

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDgnome/evince< 3.25.91
Debiangnome/evince< 3.25.92-1+3
Debianmate-desktop/atril< 1.20.0-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vvj5-83p2-x3pp: Command injection in evince via filename when printing to PDF2022-05-13
OSV
CVE-2017-1000159: Command injection in evince via filename when printing to PDF2017-11-27
CVEList
CVE-2017-1000159: Command injection in evince via filename when printing to PDF2017-11-27

📋Vendor Advisories

3
Ubuntu
Evince vulnerability2017-12-04
Red Hat
evince: Command injection when exporting to PDF2017-07-14
Debian
CVE-2017-1000159: atril - Command injection in evince via filename when printing to PDF. This affects vers...2017

💬Community

3
Bugzilla
CVE-2017-1000159 evince: Command injection when exporting to PDF [fedora-26]2017-12-06
Bugzilla
CVE-2017-1000159 evince: Command injection when exporting to PDF2017-12-06
Bugzilla
CVE-2017-1000159 evince: Command injection when exporting to PDF [fedora-25]2017-12-06
CVE-2017-1000159 — OS Command Injection in Gnome Evince | cvebase