CVE-2020-9359
published 2020-03-24CVE-2020-9359: KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
PriorityP424medium5.3CVSS 3.1
AVLACLPRNUIRSUCLILAL
EPSS
1.45%
70.5th percentile
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | okular | < okular 4:19.12.3-2 (bookworm) | okular 4:19.12.3-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| kde | okular | < 1.10.0 | 1.10.0 |
| kde | okular | >= 0 < 4:19.12.3-2 | 4:19.12.3-2 |
| kde | okular | >= 0 < 4:19.12.3-2 | 4:19.12.3-2 |
| kde | okular | >= 0 < 4:19.12.3-2 | 4:19.12.3-2 |
| kde | okular | >= 0 < 4:19.12.3-2 | 4:19.12.3-2 |
| kde | okular | >= 19.12.0 < 19.12.3 | 19.12.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
okular: local binary execution via specially crafted PDF files
vendor_redhat·2020-03-12·CVSS 5.3
CVE-2020-9359 [MEDIUM] CWE-184 okular: local binary execution via specially crafted PDF files
okular: local binary execution via specially crafted PDF files
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
Mitigation: There's no available mitigation other than don't open PDF files from untrusted sources.
Debian
CVE-2020-9359: okular - KDE Okular before 1.10.0 allows code execution via an action link in a PDF docum...
vendor_debian·2020·CVSS 5.3
CVE-2020-9359 [MEDIUM] CVE-2020-9359: okular - KDE Okular before 1.10.0 allows code execution via an action link in a PDF docum...
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
Scope: local
bookworm: resolved (fixed in 4:19.12.3-2)
bullseye: resolved (fixed in 4:19.12.3-2)
forky: resolved (fixed in 4:19.12.3-2)
sid: resolved (fixed in 4:19.12.3-2)
trixie: resolved (fixed in 4:19.12.3-2)
GHSA
GHSA-jmvc-hx3f-5mj7: KDE Okular before 1
ghsa_unreviewed·2022-05-24
CVE-2020-9359 [MEDIUM] CWE-20 GHSA-jmvc-hx3f-5mj7: KDE Okular before 1
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
OSV
CVE-2020-9359: KDE Okular before 1
osv·2020-03-24·CVSS 5.3
CVE-2020-9359 [MEDIUM] CVE-2020-9359: KDE Okular before 1
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9359 okular: local binary execution via specially crafted PDF files [epel-8]
bugzilla·2020-03-20·CVSS 5.3
CVE-2020-9359 [MEDIUM] CVE-2020-9359 okular: local binary execution via specially crafted PDF files [epel-8]
CVE-2020-9359 okular: local binary execution via specially crafted PDF files [epel-8]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-8.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for t
Bugzilla
CVE-2020-9359 okular: local binary execution via specially crafted PDF files [fedora-all]
bugzilla·2020-03-20·CVSS 5.3
CVE-2020-9359 [MEDIUM] CVE-2020-9359 okular: local binary execution via specially crafted PDF files [fedora-all]
CVE-2020-9359 okular: local binary execution via specially crafted PDF files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-9359 okular: local binary execution via specially crafted PDF files
bugzilla·2020-03-20·CVSS 5.3
CVE-2020-9359 [MEDIUM] CVE-2020-9359 okular: local binary execution via specially crafted PDF files
CVE-2020-9359 okular: local binary execution via specially crafted PDF files
Okular can be tricked into executing local binaries via specially crafted PDF files.
References:
https://kde.org/info/security/advisory-20200312-1.txt
Upstream commit:
https://invent.kde.org/kde/okular/-/commit/6a93a033b4f9248b3cd4d04689b8391df754e244
Discussion:
Created okular tracking bugs for this issue:
Affects: epel-8 [bug 1815653]
Affects: fedora-all [bug 1815652]
---
External References:
https://kde.org/info/security/advisory-20200312-1.txt
---
There's an issue on Okular. When processing actions taken by the user when reading a PDF file, Okular has the capability of open other link files. This is done using KRun() object from KDE API. The KRun() class, checks the mimetype and properly executed th
https://invent.kde.org/kde/okular/-/commit/6a93a033b4f9248b3cd4d04689b8391df754e244https://kde.org/info/security/advisory-20200312-1.txthttps://lists.debian.org/debian-lts-announce/2020/03/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2TY3O6UWX2XTP7PISPTZ6FYRDFU4UF66/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AW6GJ3AKGXOMTDHNZBMSXDTWNJJRFBDH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G3HL3F6JLCSRLPFZ47735F5STPJWDVR4/https://security.gentoo.org/glsa/202007-47https://invent.kde.org/kde/okular/-/commit/6a93a033b4f9248b3cd4d04689b8391df754e244https://kde.org/info/security/advisory-20200312-1.txthttps://lists.debian.org/debian-lts-announce/2020/03/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2TY3O6UWX2XTP7PISPTZ6FYRDFU4UF66/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AW6GJ3AKGXOMTDHNZBMSXDTWNJJRFBDH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G3HL3F6JLCSRLPFZ47735F5STPJWDVR4/https://security.gentoo.org/glsa/202007-47
2020-03-24
Published