Ubuntu 10.04 LTS / 10.10 / 11.04 : evince vulnerability (USN-1347-1)

Ubuntu Security Notice (C) 2012-2013 Canonical, Inc. / NASL script (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

It was discovered that Evince did not properly parse AFM font files
when processing DVI files. If a user were tricked into opening a
specially crafted DVI file, an attacker could cause Evince to crash or
potentially execute arbitrary code with the privileges of the user
invoking the program.

In the default installation, attackers would be isolated by the Evince
AppArmor profile.

Solution :

Update the affected libevdocument2 and / or libevdocument3 packages.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.0
(CVSS2#E:U/RL:OF/RC:ND)
Public Exploit Available : false

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 57698 ()

Bugtraq ID: 47168

CVE ID: CVE-2011-0433