← back
CVE-2017-1000083

CVE-2017-1000083

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 51%
from disclosure to weapon420 days
Published on NVDSep 5
1st PoC+420d
metasploitJul 13
exploitation probability
51%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.