Vulnerability Bulletins

DSA-3911 evince - security update

   
Affected software Debian
 
Felix Wilhelm discovered that the Evince document viewer made insecureuse of tar when opening tar comic book archives (CBT). Opening amalicious CBT archive could result in the execution of arbitrary code.This update disables the CBT format entirely.

More info:

https://www.debian.org/security/2017/dsa-3911