CVE-2023-51698

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-51698
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-51698.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-51698
Aliases
  • GHSA-34rr-j8v9-v4p2
Related
Published
2024-01-12T21:15:10Z
Modified
2024-10-12T11:12:57.991080Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.

References

Affected packages

Debian:11 / atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.24.0-1+deb11u1

Affected versions

1.*

1.24.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.26.0-2+deb12u2

Affected versions

1.*

1.26.0-2
1.26.0-2+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/mate-desktop/atril

Affected ranges

Type
GIT
Repo
https://github.com/mate-desktop/atril
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

atril-1.*

atril-1.10.0
atril-1.10.1
atril-1.11.0
atril-1.12.0
atril-1.2.0
atril-1.2.1
atril-1.7.0
atril-1.7.1
atril-1.7.2
atril-1.7.90
atril-1.8.0
atril-1.9.0
atril-1.9.1
atril-1.9.2
atril-1.9.90

mate-document-viewer-1.*

mate-document-viewer-1.1.0
mate-document-viewer-1.1.1
mate-document-viewer-1.4.0
mate-document-viewer-1.5.0
mate-document-viewer-1.6.0
mate-document-viewer-1.6.1

v1.*

v1.12.0
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.16.0
v1.16.1
v1.17.0
v1.17.1
v1.18.0
v1.19.0
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.19.5
v1.19.6
v1.20.0
v1.21.0
v1.21.1
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.27.0