Description
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1204-1 | evince security update |
Debian DLA |
DLA-1881-1 | evince security update |
Debian DLA |
DLA-1882-1 | atril security update |
Debian DSA |
DSA-4624-1 | evince security update |
EUVD |
EUVD-2017-1444 | Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. |
Ubuntu USN |
USN-3503-1 | Evince vulnerability |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:53:07.215Z
Reserved: 2017-11-27T00:00:00.000Z
Link: CVE-2017-1000159
No data.
Status : Modified
Published: 2017-11-27T15:29:00.243
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-1000159
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN