• Vulnerabilities in various GTK-based PDF readers

    From LWN.net@1337:1/100 to All on Thu May 21 22:15:07 2026
    Vulnerabilities in various GTK-based PDF readers

    Date:
    Thu, 21 May 2026 21:05:20 +0000

    Description:
    Michael Catanzaro has disclosed a
    command-injection vulnerability affecting a number of GTK-based PDF
    readers; exploits included: They contain a script for building malicious polyglot PDFs that are
    simultaneously both valid PDF files and also valid ELF
    binaries. When the user opens the PDF in the PDF viewer and clicks
    on a malicious link embedded in the PDF, the PDF abuses the command
    injection vulnerability to load itself as a GTK module using the
    `--gtk-module` command line flag. It can then execute arbitrary
    code via its library constructor. That flag was removed in GTK 4,
    which is why the vulnerability is much less serious for Papers than
    it is for Evince, Atril, and Xreader.

    ======================================================================
    Link to news story:
    https://lwn.net/Articles/1073944/


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)