Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2024.0224
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2024-0224)
Summary:The remote host is missing an update for the 'atril' package(s) announced via the MGASA-2024-0224 advisory.
Description:Summary:
The remote host is missing an update for the 'atril' package(s) announced via the MGASA-2024-0224 advisory.

Vulnerability Insight:
Atril Document Viewer is the default document reader of the MATE desktop
environment for Linux. A path traversal and arbitrary file write
vulnerability exists in versions of Atril prior to 1.26.2. This
vulnerability is capable of writing arbitrary files anywhere on the
filesystem to which the user opening a crafted document has access. The
only limitation is that this vulnerability cannot be exploited to
overwrite existing files, but that doesn't stop an attacker from
achieving Remote Command Execution on the target system.
(CVE-2023-52076)

Affected Software/OS:
'atril' package(s) on Mageia 9.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-52076
https://github.com/mate-desktop/atril/commit/e70b21c815418a1e6ebedf6d8d31b8477c03ba50
https://github.com/mate-desktop/atril/releases/tag/v1.26.2
https://github.com/mate-desktop/atril/security/advisories/GHSA-6mf6-mxpc-jc37
https://lists.debian.org/debian-lts-announce/2024/06/msg00003.html
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.