Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.
The vulnerability results from improper handling of CBT files, which are TAR archives. An attacker prepares a malicious CBT file containing a properly constructed file path or name in the archive, allowing injection of arbitrary system commands (command injection, CWE-78). When such a file is opened by a user or when clicking on a crafted link, the Atril application executes the injected commands with the privileges of the logged-in user.
Attacker gains immediate remote access to the victim's system with their privileges, which may lead to full system takeover, data theft, and further lateral movement in the network.
Apply the patch available in commit ce41df6467521ff9fd4f16514ae7d6ebb62eb1ed in the mate-desktop/atril GitHub repository. Fedora distribution users should install the updated package according to communications published on Fedora mailing lists. Until updates are applied, it is recommended not to open CBT files from untrusted sources.
Mate-Desktop Atril — versions specified in producer references (before patch from commit ce41df6)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:LMate Desktop Atril
APPMate-Desktop≤ 1.26.3
Related vulnerabilities
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path travers...
Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversa...
mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view scree...
Domyślna konfiguracja mate-settings-daemon 1.5.3 umożliwia lokalnym użytkownikom zmianę strefy czasowej system...