[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1882-1] atril security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : atril
Version        : 1.8.1+dfsg1-4+deb8u2
CVE ID         : CVE-2017-1000159 CVE-2019-11459 CVE-2019-1010006

A few issues were found in Atril, the MATE document viewer.

CVE-2017-1000159

    When printing from DVI to PDF, the dvipdfm tool was called without
    properly sanitizing the filename, which could lead to a command
    injection attack via the filename.

CVE-2019-11459

    The tiff_document_render() and tiff_document_get_thumbnail() did
    not check the status of TIFFReadRGBAImageOriented(), leading to
    uninitialized memory access if that funcion fails.

CVE-2019-1010006

    Some buffer overflow checks were not properly done, leading to
    application crash or possibly arbitrary code execution when
    opening maliciously crafted files.

For Debian 8 "Jessie", these problems have been fixed in version
1.8.1+dfsg1-4+deb8u2.

We recommend that you upgrade your atril packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl1Sr7sACgkQnUbEiOQ2
gwLLDA//TEu8+dtgHdyxsQ1/QbND4tQzkZmxnwuLXslnJKDYhivUO0119f/gJuW8
bfzN0bBJ+A+j19kkY1RXp2ZNIEj4vXSKiw+he8vDY8jzMe/jflA7n9ot2faX0an3
FFeGC6gpcfYi3O/YDFV4Bs8wDKaWIlwmd3FvRfBQggRtnlNUMTkTymkA6ZyViCrO
uCTSKG9eEpx63wUVUTLASC+t5XpUNEcgCI1CZ3jxWoHMU8o4USRecDoyxPBQ3LJy
1uya0IZXMW7+qr2CuQGW5py5h/LAmyoaIEGA+a4+MnuoYn9pBRSI1KQ9bTFNcJiw
PO0ReSrVVbwZsZYCvfGDJlNEEAGbEMjdSvKB9q5peOrkoIxMQnw9a2rwLWgOeY8v
TfEct4YwUI0Em75J3ltW6wJzdxeJs485UqxqZDrDzDt5FmxQI0y0vDWBoF127Bzx
EaG5RG3fTDIkwKJjsq3z3ttxYrHWQE3oGzfuIPXc5vKJ++OuktXeTXbPMVE+/QZX
sdxc7gnS0Nzfbnu33GDE80rgQNjRQI4gPJc4cJyVGBis3DOGk4jKpVZOuR2m1Pob
+B+7EPla4DZVT04XfhVSwDdhlwtBdTHSZqLTtZNAPvcSuiGJLd6X8hTD6K5tl6Tj
nbc1QdDGaRURAntkSOBla/REbIc1gUSfTMBaCWRsQ2sPer3dRvs=
=y+9p
-----END PGP SIGNATURE-----


Reply to: