USN-8295-1: Evince vulnerability
Source: Ubuntu
Published:
<p>Evince could be made to run programs as your login if it opened a specially crafted file.</p> <p>It was discovered that Evince did not properly sanitize command-line arguments in PDF /GoToR actions. If a user opened a specially crafted PDF file, an attacker could possibly use this issue to execut