SB2020021502 - Debian update for evince
Published: February 15, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Command injection (CVE-ID: CVE-2017-1000159)
The vulnerability allows a remote attacker to perform command injection attack on the target system.The weakness exists due to an error when handling printing certain DVI files. A remote attacker can trick the victim into opening and printing a specially-named DVI file, inject arbitrary commands and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
2) Buffer overflow (CVE-ID: CVE-2019-1010006)
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on a targeted system.
The vulnerability exists due to a buffer overflow condition in the "backend/tiff/tiff-document.c" when handling PDF files. A remote attacker can trick a victim to open a specially crafted PDF file and execute arbitrary code or cause a DoS condition on the targeted system.
3) Access of Uninitialized Pointer (CVE-ID: CVE-2019-11459)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due tothe TIFFReadRGBAImageOriented() function called from tiff_document_render() and tiff_document_get_thumbnail() functions in the backend/tiff/tiff-document.c in GNOME Evince returns uninitialized memory instead of false, when failing to read an image. A remote attacker can gain access to sensitive information on the system.
Remediation
Install update from vendor's website.