Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Debian Security Advisory 5688-1[6]
- Authored by Debian[7] | Site debian.org[8]
-
Debian Linux Security Advisory 5688-1 - It was discovered that missing input sanitising in the Atril document viewer could result in writing arbitrary files in the users home directory if a malformed epub document is opened.
- systems | linux[9], debian[10]
- advisories | CVE-2023-52076[11]
- SHA-256 |
ce64dbc7042d36045420d8024d1749d0ba1c9d8b43b3a218aec4ed4925c70038 - Download[12] | Favorite[13] | View[14]
Change Mirror[15] Download[16]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5688-1 Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser.
https://www.debian.org/security/ Moritz Muehlenhoff
May 12, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : atril
CVE ID : CVE-2023-52076
It was discovered that missing input sanitising in the Atril document
viewer could result in writing arbitrary files in the users home directory
if a malformed epub document is opened.
For the oldstable distribution (bullseye), this problem has been fixed
in version 1.24.0-1+deb11u1. This update also disables support for
comic book archives, mitigating CVE-2023-51698.
For the stable distribution (bookworm), this problem has been fixed in
version 1.26.0-2+deb12u3.
We recommend that you upgrade your atril packages.
For the detailed security status of atril please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/atril
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser.
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmZAwWEACgkQEMKTtsN8
TjYqAw/+OF7wq08UNm4f0fbj/1xH8rFftCj/pnB1XGjkPiOPQA7cYDHUM0kRjEQt
4MDCxzQXs5gWOR20XhZUUij95xj2d29t99N9xRWdhoC49pWOfAUKRNojrt+aa/LX
SzEd2tQTWD+RuFd0ODUVJ8EYwwTH+U+NA2qVRnrXVS2PT3rUIotdXjIUPPe+LII+
UX/wx3c8AKBk8UH+2bJJnLpZ26KqzcoQR4Qx4hClx0mvDFtmbKPANBeiiJSmy3er
Y9VG7PSDqI0m+N67Sa5mOqOr9rVFNpqXJegSm/RIEvN/K3J+HKtxpkDyWIsG8tro
ZxA53WanVGLjWVU9HnE+XtwMvEQcjlg2r/vaN/oisbdFzybbBFrvoITVBQTeKnMP
GVI3IIPGRBlHYGFJpvhc25xZfVphYlqB9gVwDIlkIIPCa23fr4KilCK/k7fDTrF/
3ae91LnzyLMIxBIIDmtEbdWxKxCnizZtTpZf0Tdy1srueqdW5FdqT0fl/SZqtWhJ
2g/uAROk4lOvs8H609it8UCK4X9PPZwYci7gzKHBpzQ5vuI+oAjL9EN41R4sahq6
Wl0Z7n5gFcsfpfKSkdFosLMylsfQ3h2Wfdw/obiXr9VYjIUQHBdQ6zUgOnwdhNp8
hvwY2WNDWrpwg2mu0cp8zRcCFLeHtfYcza9VWtiJcEa+6WAAemQ=
=6TWQ
-----END PGP SIGNATURE-----
File Tags
- ActiveX[22] (933)
- Advisory[23] (85,181)
- Arbitrary[24] (16,697)
- BBS[25] (2,859)
- Bypass[26] (1,834)
- CGI[27] (1,032)
- Code Execution[28] (7,667)
- Conference[29] (689)
- Cracker[30] (844)
- CSRF[31] (3,375)
- DoS[32] (24,688)
- Encryption[33] (2,383)
- Exploit[34] (52,879)
- File Inclusion[35] (4,253)
- File Upload[36] (987)
- Firewall[37] (822)
- Info Disclosure[38] (2,861)
- Intrusion Detection[39] (909)
- Java[40] (3,128)
- JavaScript[41] (890)
- Kernel[42] (7,047)
- Local[43] (14,723)
- Magazine[44] (586)
- Overflow[45] (13,088)
- Perl[46] (1,431)
- PHP[47] (5,206)
- Proof of Concept[48] (2,373)
- Protocol[49] (3,704)
- Python[50] (1,605)
- Remote[51] (31,465)
- Root[52] (3,620)
- Rootkit[53] (523)
- Ruby[54] (620)
- Scanner[55] (1,650)
- Security Tool[56] (7,988)
- Shell[57] (3,261)
- Shellcode[58] (1,217)
- Sniffer[59] (900)
- Spoof[60] (2,266)
- SQL Injection[61] (16,544)
- TCP[62] (2,426)
- Trojan[63] (689)
- UDP[64] (899)
- Virus[65] (669)
- Vulnerability[66] (32,706)
- Web[67] (9,900)
- Whitepaper[68] (3,775)
- x86[69] (967)
- XSS[70] (18,191)
- Other[71]
File Archives
- May 2024[72]
- April 2024[73]
- March 2024[74]
- February 2024[75]
- January 2024[76]
- December 2023[77]
- November 2023[78]
- October 2023[79]
- September 2023[80]
- August 2023[81]
- July 2023[82]
- June 2023[83]
- Older[84]
Systems
- AIX[85] (429)
- Apple[86] (2,078)
- BSD[87] (376)
- CentOS[88] (58)
- Cisco[89] (1,927)
- Debian[90] (7,038)
- Fedora[91] (1,693)
- FreeBSD[92] (1,246)
- Gentoo[93] (4,499)
- HPUX[94] (880)
- iOS[95] (373)
- iPhone[96] (108)
- IRIX[97] (220)
- Juniper[98] (69)
- Linux[99] (49,580)
- Mac OS X[100] (691)
- Mandriva[101] (3,105)
- NetBSD[102] (256)
- OpenBSD[103] (488)
- RedHat[104] (15,745)
- Slackware[105] (941)
- Solaris[106] (1,611)
- SUSE[107] (1,444)
- Ubuntu[108] (9,490)
- UNIX[109] (9,397)
- UnixWare[110] (187)
- Windows[111] (6,656)
- Other[112]
- Services
- Security Services[123]
- Hosting By
- Rokasec[124]
Read more https://packetstormsecurity.com/files/178556/dsa-5688-1.txt


