|
|
Log in / Subscribe / Register

Ubuntu alert USN-8295-1 (evince)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8295-1] Evince vulnerability
Date:  Fri, 22 May 2026 14:29:02 +0000
Message-ID:  <E1wQQs2-0003Dk-K0@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8295-1 May 22, 2026 evince vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Evince could be made to run programs as your login if it opened a specially crafted file. Software Description: - evince: Document viewer Details: It was discovered that Evince did not properly sanitize command-line arguments in PDF /GoToR actions. If a user opened a specially crafted PDF file, an attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS evince 49~alpha-2ubuntu2.1 evince-common 49~alpha-2ubuntu2.1 Ubuntu 25.10 evince 48.1-3ubuntu2.1 evince-common 48.1-3ubuntu2.1 Ubuntu 24.04 LTS evince 46.3.1-0ubuntu1.1 evince-common 46.3.1-0ubuntu1.1 Ubuntu 22.04 LTS evince 42.3-0ubuntu3.2 evince-common 42.3-0ubuntu3.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8295-1 CVE-2026-46529 Package Information: https://launchpad.net/ubuntu/+source/evince/49~alpha-2ubu... https://launchpad.net/ubuntu/+source/evince/48.1-3ubuntu2.1 https://launchpad.net/ubuntu/+source/evince/46.3.1-0ubunt... https://launchpad.net/ubuntu/+source/evince/42.3-0ubuntu3.2


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoQaCEACgkQcpJm3tlz hgG6LQ/+PsmUZSrGFCEZM2s8OJC0466/o0jtyKAAvprrvrhZFIsoM17gTAAVXzYv 9RiybBylvU+uVmt/4+k1/Z2U1GQbOLzzul4M7/v1YVyksPqJE0OOHGBI1+Uwaxob MRgbpaLzV9+OLRAB7HrQ5gCmfk1aIMaqEacCxjIG2NlnIdW0dD2AnaN3nj05mVjl xL0VUP0hyO1THXz/nz+KTaVvr1TTKF84l2o43cnpogdr9Wu/3VdNCD+x47G3lQmU dtNt31/M07tyeykew9DG2xUfyU6KYjxSB/L5Ahrzb3lpMKEZXbFpf/r2ZU/WXCIh DG5RA/BmsCUiIhQqqfZJtNIVEZEy9fqrchkj0q1RdY6XvOFpHvqIdUV1jJGDvYQM aDGucKCQNLTVelL9wYwBi8Trj1Yl8bEQp8G1+e+uKM1+IxiJsatPHMAJ/gIHpTJe mjX/1QhIcEGB+GdmXfhId2cHFFkbg9MDs8vyBAT2KKo6HG7MEr/f+56sbdvZNmtV 4uqtmnim8+mhiGRj0mjZSoqj2vcVJX6OHj2T/XWVBOIgVv3SIFbMsaTCg0WCsSpp 4NUKuba/105vyvyYAQCA70cKEc+9GscXS/bCdkKs7Z5xrFQ7gGhnuWtJLuLF7BJ3 /ZSksG9IGfx9CiwIHUdIt6ZGZ3qG7kQ1+dx6o6JRmIqNthaykCg= =0gJn -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds