[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4624-1 evince -- evince

ID: oval:org.secpod.oval:def:69951Date: (C)2021-03-03   (M)2024-02-08
Class: PATCHFamily: unix




Several vulnerabilities were discovered in evince, a simple multi-page document viewer. CVE-2017-1000159 Tobias Mueller reported that the DVI exporter in evince is susceptible to a command injection vulnerability via specially crafted filenames. CVE-2019-11459 Andy Nguyen reported that the tiff_document_render and tiff_document_get_thumbnail functions in the TIFF document backend did not handle errors from TIFFReadRGBAImageOriented, leading to disclosure of uninitialized memory when processing TIFF image files. CVE-2019-1010006 A buffer overflow vulnerability in the tiff backend could lead to denial of service, or potentially the execution of arbitrary code if a specially crafted PDF file is opened.

Platform:
Linux Mint 4
Product:
evince
Reference:
DSA-4624-1
CVE-2017-1000159
CVE-2019-11459
CVE-2019-1010006
CVE    3
CVE-2017-1000159
CVE-2019-1010006
CVE-2019-11459
CPE    2
cpe:/a:gnome:evince
cpe:/o:linux_mint:linux_mint:4

© SecPod Technologies