Exploitation Summary
EIP tracks 5 public exploits for CVE-2017-1000083.
PoCs published by Metasploit, Matlink, matlink, including Metasploit module exploits/multi/fileformat/evince_cbt_cmd_injection.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Evince before 3.24.1 via a malicious `.cbt` file. It crafts a tar archive with a checkpoint action to execute arbitrary commands when the file is opened.
Description
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
Exploits (5)
This Metasploit module exploits a command injection vulnerability in Evince before 3.24.1 via a malicious `.cbt` file. It crafts a tar archive with a checkpoint action to execute arbitrary commands when the file is opened.
This exploit leverages a command injection vulnerability in Evince (CVE-2017-1000083) by crafting a malicious .cbt file with a checkpoint action that executes arbitrary commands when opened. The PoC demonstrates RCE via the `--checkpoint-action` parameter in a tar archive.
This Dockerfile sets up a vulnerable environment for CVE-2017-1000083, exploiting a command injection vulnerability in Evince via a crafted CBT file. The exploit triggers arbitrary command execution (e.g., launching Firefox) when the file is opened.
This Dockerfile sets up an environment to exploit CVE-2017-1000083, a vulnerability in Atril and Nautilus involving improper handling of .cbt files. The setup includes vulnerable software (Atril, Nautilus) and a crafted .cbt file (covfefe.tar) to trigger the exploit.
This Metasploit module exploits a command injection vulnerability in Evince before version 3.24.1 by crafting a malicious .cbt file. The exploit leverages the checkpoint-action feature in tar archives to execute arbitrary commands when the file is opened.
References (8)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H