backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "evince",
"binary_version": "3.10.3-0ubuntu10.3"
},
{
"binary_name": "evince-common",
"binary_version": "3.10.3-0ubuntu10.3"
},
{
"binary_name": "evince-gtk",
"binary_version": "3.10.3-0ubuntu10.3"
},
{
"binary_name": "gir1.2-evince-3.0",
"binary_version": "3.10.3-0ubuntu10.3"
},
{
"binary_name": "libevdocument3-4",
"binary_version": "3.10.3-0ubuntu10.3"
},
{
"binary_name": "libevince-dev",
"binary_version": "3.10.3-0ubuntu10.3"
},
{
"binary_name": "libevview3-3",
"binary_version": "3.10.3-0ubuntu10.3"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "atril",
"binary_version": "1.12.2-1ubuntu0.2"
},
{
"binary_name": "atril-common",
"binary_version": "1.12.2-1ubuntu0.2"
},
{
"binary_name": "gir1.2-atril",
"binary_version": "1.12.2-1ubuntu0.2"
},
{
"binary_name": "libatrildocument-dev",
"binary_version": "1.12.2-1ubuntu0.2"
},
{
"binary_name": "libatrildocument3",
"binary_version": "1.12.2-1ubuntu0.2"
},
{
"binary_name": "libatrilview-dev",
"binary_version": "1.12.2-1ubuntu0.2"
},
{
"binary_name": "libatrilview3",
"binary_version": "1.12.2-1ubuntu0.2"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "evince",
"binary_version": "3.18.2-1ubuntu4.1"
},
{
"binary_name": "evince-common",
"binary_version": "3.18.2-1ubuntu4.1"
},
{
"binary_name": "evince-gtk",
"binary_version": "3.18.2-1ubuntu4.1"
},
{
"binary_name": "gir1.2-evince-3.0",
"binary_version": "3.18.2-1ubuntu4.1"
},
{
"binary_name": "libevdocument3-4",
"binary_version": "3.18.2-1ubuntu4.1"
},
{
"binary_name": "libevince-dev",
"binary_version": "3.18.2-1ubuntu4.1"
},
{
"binary_name": "libevview3-3",
"binary_version": "3.18.2-1ubuntu4.1"
}
]
}