[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6286-1] evince security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6286-1] evince security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Thu, 21 May 2026 11:55:10 +0000 Message-id: <[🔎] E1wQ1za-00000002Q6n-3RBN@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6286-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : evince CVE ID : CVE-2026-46529 It was discovered that evince, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For the oldstable distribution (bookworm), this problem has been fixed in version 43.1-2+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 48.1-3+deb13u1. We recommend that you upgrade your evince packages. For the detailed security status of evince please refer to its security tracker page at: https://security-tracker.debian.org/tracker/evince Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoO8ZBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SNqA//bT6vs0CQ8ARc3W5vcckqTSgUc9yBUt6/Z/d2eg2xQ13lXMArckiAJESD jC2YoRcjp8TGisw5gw9dryuSnE2bNo9ufoSQeGQPKt7jvX0gLjZ+dQn0nw5scbmn jKyGxsOKF+4zzhkic89eFQ24gelkvLCmEk3ZnweidZJ4lxfW5ZfuB+V2B3sr0qhc K2osI1s3w7o0JNd0pzeNjBEcbr9A0GsV9IkBbqM4jx1FjqSDhCAtchaXb7DwaGnY lCmDK0Vbkiq2Dl/54tPBbos4cxBxRLrZReHj4tzxvVSZmQ577FKSem5KXleYhEZU RDcyiYlL9Dwpim9MbgkknOs5u3kz4a7hxhQc1IYqIHjFMdzTYebpqyJ2qLXBAp0h hSA0dlxWCR+RqlEnC01ineJ9O/uUE3EvqoSab+yPijmZ9zH3Dh/G8bUGBMi9uozY rQZRVYqbWHeOKPDEx6Dh5XSGSISz21ZT8qfxTakuEDg6+pPtMGZTzoB6paKh0zaQ F1cYmbUzcyykTJKM9u8e1nY8pVby5pmQ3RETcbpFNmC9Ol/QdQ9G4QvnHABFlE1v SSKwn7Co0/8XhjZ+armSZpI5vtEe4ptxfZyNsherCqvr16c5MX5W+3gl6sAfFjjn p+Qyt3m9LbRvz5vUoCjz0BJYq705qi6MPetIwgrkAaCFLPUHYPk= =/c3P -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6285-1] bind9 security update Previous by thread: [SECURITY] [DSA 6285-1] bind9 security update Index(es): Date Thread
The evince document viewer contains a command injection vulnerability (CVE-2026-46529) triggered by opening a maliciously crafted PDF file. For Debian oldstable (bookworm), the issue is fixed in version 43.1-2+deb12u1; for stable (trixie), it is fixed in version 48.1-3+deb13u1. Users are advised to upgrade their evince packages to these patched versions.