USN-7274-1: Atril vulnerabilities
18 February 2025
Atril could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- atril - Official Document Viewer of the MATE Desktop Environment
Details
It was discovered that Atril incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service
or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)
Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)
Febin Mon Saji discovered that Atril incorrectly handled certain
compressed files. A remote attacker could possibly use this issue to
cause a denial of service or to execute arbitrary code. (CVE-2023-51698)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
atril
-
1.20.1-2ubuntu2+esm2
Available with Ubuntu Pro
-
atril-common
-
1.20.1-2ubuntu2+esm2
Available with Ubuntu Pro
-
libatrildocument3
-
1.20.1-2ubuntu2+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.