CVE-2018-1000801 PUBLISHED

okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1

EPSS 2.18% · 84.2th percentile

Risk Scores

EPSS Score
2.18%
84.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSokular*, 0, 4:17.08.3-0ubuntu1
Ubuntu:16.04:LTSokular0, 4:15.08.2-0ubuntu2, *

Timeline

References

Open in Interactive Console →