Language:
https://bugzilla.suse.com/show_bug.cgi?id=1046856
Severity: High
ID: 103111
File Name: suse_SU-2017-2390-1.nasl
Version: 3.10
Type: local
Agent: unix
Family: SuSE Local Security Checks
Published: 9/11/2017
Updated: 1/6/2021
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Factor: High
Score: 7.4
Risk Factor: Medium
Base Score: 6.8
Temporal Score: 5.6
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
Risk Factor: High
Base Score: 7.8
Temporal Score: 7.2
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
CPE: p-cpe:/a:novell:suse_linux:evince-plugin-psdocument-debuginfo, p-cpe:/a:novell:suse_linux:evince-debugsource, p-cpe:/a:novell:suse_linux:evince-browser-plugin-debuginfo, p-cpe:/a:novell:suse_linux:typelib-1_0-evincedocument, p-cpe:/a:novell:suse_linux:evince-debuginfo, p-cpe:/a:novell:suse_linux:libevdocument3-4-debuginfo, p-cpe:/a:novell:suse_linux:evince-plugin-pdfdocument, p-cpe:/a:novell:suse_linux:evince-plugin-tiffdocument, p-cpe:/a:novell:suse_linux:evince-plugin-djvudocument, p-cpe:/a:novell:suse_linux:nautilus-evince-debuginfo, p-cpe:/a:novell:suse_linux:libevdocument3, p-cpe:/a:novell:suse_linux:evince-plugin-xpsdocument-debuginfo, p-cpe:/a:novell:suse_linux:evince-plugin-pdfdocument-debuginfo, p-cpe:/a:novell:suse_linux:libevview3, p-cpe:/a:novell:suse_linux:evince-plugin-dvidocument, p-cpe:/a:novell:suse_linux:evince, p-cpe:/a:novell:suse_linux:nautilus-evince, p-cpe:/a:novell:suse_linux:evince-plugin-dvidocument-debuginfo, p-cpe:/a:novell:suse_linux:evince-browser-plugin, p-cpe:/a:novell:suse_linux:evince-plugin-djvudocument-debuginfo, cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:evince-plugin-psdocument, p-cpe:/a:novell:suse_linux:evince-plugin-xpsdocument, p-cpe:/a:novell:suse_linux:evince-plugin-tiffdocument-debuginfo, p-cpe:/a:novell:suse_linux:typelib-1_0-evinceview, p-cpe:/a:novell:suse_linux:libevview3-3-debuginfo
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 9/8/2017
Vulnerability Publication Date: 9/5/2017
Metasploit (Evince CBT File Command Injection)
CVE: CVE-2017-1000083