backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
{ "binaries": [ { "binary_name": "evince", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "evince-common", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "evince-dbg", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "evince-dbgsym", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "evince-gtk", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "evince-gtk-dbgsym", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "gir1.2-evince-3.0", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "gir1.2-evince-3.0-dbgsym", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "libevdocument3-4", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "libevdocument3-4-dbgsym", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "libevince-dev", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "libevince-dev-dbgsym", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "libevview3-3", "binary_version": "3.10.3-0ubuntu10.3" }, { "binary_name": "libevview3-3-dbgsym", "binary_version": "3.10.3-0ubuntu10.3" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "atril", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "atril-common", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "atril-dbg", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "atril-dbgsym", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "gir1.2-atril", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrildocument-dev", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrildocument3", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrildocument3-dbg", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrildocument3-dbgsym", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrilview-dev", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrilview3", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrilview3-dbg", "binary_version": "1.12.2-1ubuntu0.2" }, { "binary_name": "libatrilview3-dbgsym", "binary_version": "1.12.2-1ubuntu0.2" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "evince", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "evince-common", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "evince-dbg", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "evince-dbgsym", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "evince-gtk", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "gir1.2-evince-3.0", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "libevdocument3-4", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "libevdocument3-4-dbgsym", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "libevince-dev", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "libevview3-3", "binary_version": "3.18.2-1ubuntu4.1" }, { "binary_name": "libevview3-3-dbgsym", "binary_version": "3.18.2-1ubuntu4.1" } ], "availability": "No subscription required" }