Ubuntu has issued an advisory on June 5: https://ubuntu.com/security/notices/USN-6808-1
Status comment: (none) => Fixed upstream in 1.26.2 and patch available from upstreamSource RPM: (none) => atril-1.26.1-1.mga9.src.rpmCVE: (none) => CVE-2023-52076
Status comment: Fixed upstream in 1.26.2 and patch available from upstream => Fixed upstream in 1.26.2 and patch available from upstream and Ubuntu
This looks like the patches: Patches: upstream: https://github.com/mate-desktop/atril/commit/e70b21c815418a1e6ebedf6d8d31b8477c03ba50 Another to assign globally.
Assignee: bugsquad => pkg-bugs
Suggested advisory: ======================== The updated packages fix a security vulnerability: Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. (CVE-2023-52076) References: https://ubuntu.com/security/notices/USN-6808-1 ======================== Updated packages in core/updates_testing: ======================== atril-1.26.1-1.1.mga9 atril-dvi-1.26.1-1.1.mga9 lib(64)atril3-1.26.1-1.1.mga9 lib(64)atril-devel-1.26.1-1.1.mga9 lib(64)atril-gir1.5.0-1.26.1-1.1.mga9 from SRPM: atril-1.26.1-1.1.mga9.src.rpm
Assignee: pkg-bugs => qa-bugsStatus comment: Fixed upstream in 1.26.2 and patch available from upstream and Ubuntu => (none)Status: NEW => ASSIGNED
Keywords: (none) => advisory
x86_64 applied update. invoke atril. open PDF and viewed - ok
CC: (none) => westel
mga9-64 Plasma X11 nvidia-current Opened a 360 page pdf multilingual chainsaw manual with text and graphics, print to Boomaga OK.
CC: (none) => fri
MGA9-64 Plasma Wayland on HP-Pavillon. On selecting the packages in MCC Install SW from QARepo I get "Sorry, the following package cannot be selected: - lib64atril-devel-1.26.1-1.1.mga9.x86_64" Continuing test as this is not essential for the normal working of atril?? Opened different pdf files with some or more graphical contents, all displays OK. Good enough for me, if some reasonable explanation is found for the devel package.
CC: (none) => herman.viaene
CC: (none) => andrewsfarmWhiteboard: (none) => MGA9-64-OK
@Herman: I downloaded the packages with qarepo, then used MCC for install. This MGA9-64 Plasma system did NOT have Atril installed previously. Selecting the devel package wanted a rather long list of dependencies, but was OK with it when I approved the list. I backed out without actually installing because I have no need for all those development packages on this system, then went back, and installed Atril without issues. I have no idea why it was rejected on your system.
(In reply to Thomas Andrews from comment #6) > @Herman: I downloaded the packages with qarepo, then used MCC for install. > This MGA9-64 Plasma system did NOT have Atril installed previously. > Selecting the devel package wanted a rather long list of dependencies, but > was OK with it when I approved the list. I backed out without actually > installing because I have no need for all those development packages on this > system, then went back, and installed Atril without issues. > > I have no idea why it was rejected on your system. I say that he miss a package I reproduce the issue not including lib64atril-gir1 but the popup window say why can't be selected Once included I close and open again the rpmdrake aplication and I can see the same behaviour that you Thomas
Installed uneventfully. Opened a 242 page printer manual pdf with lots of diagrams/pics - handled normally (OT: Noted comment 4. 360 page chainsaw manual. What is the world coming to?)
CC: (none) => tablackwell
Validating. (In reply to Tony Blackwell from comment #8) > 360 page chainsaw manual. What is the world coming to? After reading it, you realise the manual (thick if printed) is for exercising the chainsaw on - so you do not use it on the seller ;) The carburetor setting screws need a special tool, which i needed to manufacture in my shop before i could trim it to work reliably...
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0224.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED