Skip to main content

CVE-2017-1000083

7.8
HIGHCVSS v3.1 Base Score
76.14%
HIGH RiskEPSS (99th percentile)

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

Published: 9/5/2017
Modified: 4/20/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

76.14%HIGH Exploitation Risk
99th percentile

This vulnerability has a 76.14% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

Related Vulnerabilities