Language:
Severity: High
ID: 105456
File Name: openSUSE-2017-1417.nasl
Version: 3.6
Type: local
Agent: unix
Family: SuSE Local Security Checks
Published: 12/26/2017
Updated: 1/19/2021
Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus
Risk Factor: High
Score: 7.4
Risk Factor: Medium
Base Score: 6.8
Temporal Score: 5.6
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
Risk Factor: High
Base Score: 7.8
Temporal Score: 7.2
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
CPE: p-cpe:/a:novell:opensuse:evince-plugin-dvidocument-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-djvudocument-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-pdfdocument, p-cpe:/a:novell:opensuse:evince-plugin-xpsdocument, p-cpe:/a:novell:opensuse:evince, p-cpe:/a:novell:opensuse:libevdocument3-4, p-cpe:/a:novell:opensuse:evince-plugin-dvidocument, p-cpe:/a:novell:opensuse:evince-lang, p-cpe:/a:novell:opensuse:nautilus-evince-debuginfo, p-cpe:/a:novell:opensuse:typelib-1_0-evincedocument-3_0, p-cpe:/a:novell:opensuse:evince-plugin-tiffdocument, p-cpe:/a:novell:opensuse:evince-plugin-comicsdocument, p-cpe:/a:novell:opensuse:typelib-1_0-evinceview-3_0, p-cpe:/a:novell:opensuse:evince-devel, p-cpe:/a:novell:opensuse:evince-plugin-pdfdocument-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-psdocument-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-comicsdocument-debuginfo, p-cpe:/a:novell:opensuse:evince-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-tiffdocument-debuginfo, p-cpe:/a:novell:opensuse:libevview3-3, p-cpe:/a:novell:opensuse:evince-browser-plugin, p-cpe:/a:novell:opensuse:evince-debugsource, p-cpe:/a:novell:opensuse:evince-browser-plugin-debuginfo, cpe:/o:novell:opensuse:42.2, p-cpe:/a:novell:opensuse:evince-plugin-xpsdocument-debuginfo, cpe:/o:novell:opensuse:42.3, p-cpe:/a:novell:opensuse:libevview3-3-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-djvudocument, p-cpe:/a:novell:opensuse:nautilus-evince, p-cpe:/a:novell:opensuse:libevdocument3-4-debuginfo, p-cpe:/a:novell:opensuse:evince-plugin-psdocument
Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 12/23/2017
Vulnerability Publication Date: 9/5/2017
Metasploit (Evince CBT File Command Injection)
CVE: CVE-2017-1000083