Updated atril packages fix security vulnerability
Publication date: 08 Aug 2017Modification date: 08 Aug 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-1000083
Description
It was discovered that Atril made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely (CVE-2017-1000083).
References
SRPMS
6/core
- atril-1.18.0-1.1.mga6
5/core
- atril-1.8.1-3.1.mga5