DEBIAN-CVE-2023-51698

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2023-51698
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-51698.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2023-51698
Upstream
Published
2024-01-12T21:15:10Z
Modified
2025-09-19T07:33:32.166252Z
Summary
[none]
Details

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.

References

Affected packages

Debian:11

atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.24.0-1+deb11u1

Affected versions

1.*

1.24.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12

atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.26.0-2+deb12u2

Affected versions

1.*

1.26.0-2
1.26.0-2+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13

atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.26.1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.26.1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.25.92-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}