CVE-2019-1010006 PUBLISHED

Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.

EPSS 0.53% · 67.1th percentile

Risk Scores

EPSS Score
0.53%
67.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSevince0, 3.16.1-0ubuntu1, 3.18.1-1ubuntu1
Ubuntu:Pro:16.04:LTSatril0, 1.10.2+repack1-1, 1.12.2-1
Ubuntu:Pro:18.04:LTSatril0, 1.18.1-1, 1.18.3-1

Timeline

References

Open in Interactive Console →