📰 IT Security NachrichtenHuawei Shows Next-Generation Data Centre Optics Amid Standards Push(14.09.2026 um 09:01 Uhr)
📰 IT Security NachrichtenRobot Start-Up Skild AI Hits $100m Revenue Run-Rate(14.09.2026 um 09:31 Uhr)
📰 IT Security NachrichtenA week in security (September 7 – September 13)(14.09.2026 um 09:31 Uhr)
📰 IT Security NachrichtenIT Security News Hourly Summary 2026-09-14 10h : 8 posts(14.09.2026 um 10:00 Uhr)
📰 IT Security NachrichtenHackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process(14.09.2026 um 10:02 Uhr)
📰 IT Security NachrichtenUK Military Spends Millions On SpaceX Satellite Services(14.09.2026 um 10:02 Uhr)
🔧 AI Nachrichten OpenAI, Claude and Other Chatbot Outages Reported(03.09.2026 um 20:00 Uhr)
📰 IT Security NachrichtenHuawei Shows Next-Generation Data Centre Optics Amid Standards Push(14.09.2026 um 09:01 Uhr)
📰 IT Security NachrichtenRobot Start-Up Skild AI Hits $100m Revenue Run-Rate(14.09.2026 um 09:31 Uhr)
📰 IT Security NachrichtenA week in security (September 7 – September 13)(14.09.2026 um 09:31 Uhr)
📰 IT Security NachrichtenIT Security News Hourly Summary 2026-09-14 10h : 8 posts(14.09.2026 um 10:00 Uhr)
📰 IT Security NachrichtenHackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process(14.09.2026 um 10:02 Uhr)
📰 IT Security NachrichtenUK Military Spends Millions On SpaceX Satellite Services(14.09.2026 um 10:02 Uhr)
🔧 AI Nachrichten OpenAI, Claude and Other Chatbot Outages Reported(03.09.2026 um 20:00 Uhr)

🐧 Linux Tipps 🕛 vor 3 Monaten 1 Min Lesezeit
0

Vulnerabilities in various GTK-based PDF readers

↗ Quelle (lwn.net)
🗣️ Stimme:
Michael Catanzaro has disclosed a
command-injection vulnerability
affecting a number of GTK-based PDF
readers; exploits included:



They contain a script for building malicious polyglot PDFs that are
simultaneously both valid PDF files and also valid ELF
binaries. When the user opens the PDF in the PDF viewer and clicks
on a malicious link embedded in the PDF, the PDF abuses the command
injection vulnerability to load itself as a GTK module using the
`--gtk-module` command line flag. It can then execute arbitrary
code via its library constructor. That flag was removed in GTK 4,
which is why the vulnerability is much less serious for Papers than
it is for Evince, Atril, and Xreader.
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf lwn.net.
↗ Original-Artikel auf lwn.net lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
4 Quellen
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
1 Quelle
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
1 Quelle
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Vulnerabilities in various GTK-based PDF readers

Thematisch verwandte Begriffe: Vulnerabilities, various, GTKbased, readers · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...