Vulnerabilities in the document viewer Xreader, developed by the Linux Mint project.

Two vulnerabilities have been identified in the document viewer Xreader, developed by the Linux Mint distribution team, which may allow an attacker to execute code when opening specially crafted files in EPUB and CBT formats. The vulnerabilities have been fixed in updates Xreader 4.0.0, 3.8.5, 3.6.6, 3.2.3, and 2.6.5.

The vulnerabilities are due to errors in the code for parsing EPUB and CBT formats. In the case of EPUB, the issue (CVE-2023-44451) is related to the lack of proper escaping of special characters ("..\/ ") in parameters used for forming the file path to unpack content in the temporary files directory. In the case of CBT, the vulnerability (CVE-2023-44452) is caused by the use of unfiltered values from the file as arguments when executing the external command intltool_merge through the system() function.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster