Amazon Linux 2 Security Advisory: ALASMATE-DESKTOP1.X-2024-006
Advisory Release Date: 2024-02-15 04:09 Pacific
Advisory Updated Date: 2024-02-19 17:57 Pacific
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability. (CVE-2023-52076)
Affected Packages:
atril
Note:
This advisory is applicable to Amazon Linux 2 - Mate-desktop1.x Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update atril to update your system.
aarch64:
atril-1.20.2-1.amzn2.0.5.aarch64
atril-libs-1.20.2-1.amzn2.0.5.aarch64
atril-devel-1.20.2-1.amzn2.0.5.aarch64
atril-caja-1.20.2-1.amzn2.0.5.aarch64
atril-thumbnailer-1.20.2-1.amzn2.0.5.aarch64
atril-debuginfo-1.20.2-1.amzn2.0.5.aarch64
i686:
atril-1.20.2-1.amzn2.0.5.i686
atril-libs-1.20.2-1.amzn2.0.5.i686
atril-devel-1.20.2-1.amzn2.0.5.i686
atril-caja-1.20.2-1.amzn2.0.5.i686
atril-thumbnailer-1.20.2-1.amzn2.0.5.i686
atril-debuginfo-1.20.2-1.amzn2.0.5.i686
src:
atril-1.20.2-1.amzn2.0.5.src
x86_64:
atril-1.20.2-1.amzn2.0.5.x86_64
atril-libs-1.20.2-1.amzn2.0.5.x86_64
atril-devel-1.20.2-1.amzn2.0.5.x86_64
atril-caja-1.20.2-1.amzn2.0.5.x86_64
atril-thumbnailer-1.20.2-1.amzn2.0.5.x86_64
atril-debuginfo-1.20.2-1.amzn2.0.5.x86_64