Bug 2278867 (CVE-2023-44452) - CVE-2023-44452 xreader: Argument Injection during parsing of CBT files
Summary: CVE-2023-44452 xreader: Argument Injection during parsing of CBT files
Keywords:
Status: NEW
Alias: CVE-2023-44452
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2278870
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-05-03 12:02 UTC by TEJ RATHI
Modified: 2024-05-03 12:07 UTC (History)
0 users

Fixed In Version: xreader 3.8.5
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description TEJ RATHI 2024-05-03 12:02:43 UTC
Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22132.

https://github.com/linuxmint/xreader/commit/cd678889ecfe4e84a5cbcf3a0489e15a5e2e3736
https://www.zerodayinitiative.com/advisories/ZDI-23-1836/

Comment 1 TEJ RATHI 2024-05-03 12:07:24 UTC
Created xreader tracking bugs for this issue:

Affects: epel-7 [bug 2278870]


Note You need to log in before you can comment on or make changes to this bug.