vendor:
Evince
by:
Felix Wilhelm, Sebastian Krahmer, Matlink, bcoles
7.8
CVSS
HIGH
Command Injection
78
CWE
Product Name: Evince
Affected Version From: Before version 3.24.1
Affected Version To: 3.24.1
Patch Exists: YES
Related CWE: CVE-2017-1000083
CPE: a:evince_project:evince
Metasploit:
https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-1000083/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2017-1000083/
Platforms Tested: Kali 1.0.6, Ubuntu 16.04
2017
Evince CBT File Command Injection
This module exploits a command injection vulnerability in Evince before version 3.24.1 when opening comic book .cbt files. Some file manager software, such as Nautilus and Atril, may allow automatic exploitation without user interaction due to thumbnailer preview functionality. Note that limited space is available for the payload (<256 bytes). Reverse Bash and Reverse Netcat payloads should be sufficiently small. This module has been tested successfully on evince versions: 3.4.0-3.1 + nautilus 3.4.2-1+build1 on Kali 1.0.6; 3.18.2-1ubuntu4.3 + atril 1.12.2-1ubuntu0.3 on Ubuntu 16.04.
Mitigation:
Update to version 3.24.1 or later. Disable thumbnailer preview functionality in file manager software.