CVE-2023-51698
Atril's CBT comic book parsing vulnerable to Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.
Atril es un sencillo visor de documentos multi página. Atril es vulnerable a una vulnerabilidad crítica de inyección de comandos. Esta vulnerabilidad le brinda al atacante acceso inmediato al sistema de destino cuando el usuario de destino abre un documento manipulado o hace clic en un enlace/URL manipulado utilizando un documento CBT creado con fines malintencionados que es un archivo TAR. Hay un parche disponible en el compromiso ce41df6.
It was discovered that Atril incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. Andy Nguyen discovered that Atril incorrectly handled certain images. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 16.04 LTS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-21 CVE Reserved
- 2024-01-12 CVE Published
- 2025-02-13 CVE Updated
- 2025-02-13 EPSS Updated
- 2025-02-13 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Date | SRC |
---|---|---|
https://github.com/mate-desktop/atril/security/advisories/GHSA-34rr-j8v9-v4p2 | 2025-02-13 |
URL | Date | SRC |
---|---|---|
https://github.com/mate-desktop/atril/commit/ce41df6467521ff9fd4f16514ae7d6ebb62eb1ed | 2024-02-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mate-desktop Search vendor "Mate-desktop" | Atril Search vendor "Mate-desktop" for product "Atril" | <= 1.26.3 Search vendor "Mate-desktop" for product "Atril" and version " <= 1.26.3" | - |
Affected
|