-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4303-1 security@xxxxxxxxxx https://www.debian.org/security/ Moritz Muehlenhoff September 23, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : okular CVE ID : CVE-2018-1000801 Joran Herve discovered that the Okular document viewer was susceptible to directory traversal via malformed .okular files (annotated document archives), which could result in the creation of arbitrary files. For the stable distribution (stretch), this problem has been fixed in version 4:16.08.2-1+deb9u1. We recommend that you upgrade your okular packages. For the detailed security status of okular please refer to its security tracker page at: https://security-tracker.debian.org/tracker/okular Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlun2dEACgkQEMKTtsN8 TjYbbg//VxSpzxpHZdXRGNQP1S85jWE9LU6NbS4LKsSkKff53DLyU+hklv9WCx4f 3hxatI7oS39KWd1NqGbpKvr9VuwUwmH8tBg5TVkSE89uWZHa+Pr75k0Rjo9R9B/8 BGGHmLeeSZCI9vaDldYc9iscwXsXb9bQqlyypg0cBgpKVhK24d6MI+gaD+JdBsaG 9dwb4ftm5LCivPJ1AW5wo/ffQaP/mMEpBvkUzoi4tLZG78wkvBczxiVje7nQIQCG JbKmB8SWZBSMq2KIlnKYHekvbN+e5CLZOcTKNKnHeQYPeKo+n52kyZQBiQ+LOWWt kR5bRB5CXLIspiVlqwqtuXtrbVhjq25Yrw3N/a7sVEPE3pj8Zc4MGdphKuhUdXSY O4AavA++zfD97rEkMWUNIJYQBAJLhpyHJYFTCp4udY7/PPZevILMe8XbfslqztoM 3+cmYvRbsPvKv5mwaG/ld8hubH1IPkFqZ7StTERKLoyFFu8Ew9mSXiMQyB6UQEdK iuLcvRO/4oKq7J4hMPKuik1SfjeQ0K4Z4BI8acP6luoKbEHeUjL1jy1Dkbyy5ZhO tOAbWble3/JZkvBm42FRW0AuPdbxJZks9gN0p69Sn/DcY3Ld3CN0pNGWjfQ5ga9P e36D1Hv9N2x3E0JMb9d2joOIMOmi9HqeWy6nGYg48PRuwK5LBFk= =ayYk -----END PGP SIGNATURE-----