Security News

Cybersecurity news aggregator

🐧
HIGH Updates Debian Security

DSA-6349-1 atril - security update

A command injection vulnerability (CVE-2026-46529) in the atril MATE document viewer allows arbitrary command execution when a malicious PDF file is opened. The flaw affects the atril package in Debian stable (trixie), and it has been fixed in version 1.26.2-4+deb13u1. Administrators should upgrade their atril packages to this version immediately.
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6349-1] atril security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6349-1] atril security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Wed, 17 Jun 2026 17:35:56 +0000 Message-id: <[🔎] E1wZuBA-0000000EJtO-3fEw@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6349-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 17, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : atril CVE ID : CVE-2026-46529 Debian Bug : 1139874 It was discovered that atril, the MATE document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For the stable distribution (trixie), this problem has been fixed in version 1.26.2-4+deb13u1. We recommend that you upgrade your atril packages. For the detailed security status of atril please refer to its security tracker page at: https://security-tracker.debian.org/tracker/atril Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoy2QxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0REOg//T7kMp3DZL4VkcZ9Ab/nPWF2jsIkg9ObetE6aIPcOzgCuD1x+o1AL73hE DcKs647QIkvOdLthKpivJp0zSoXzDUqUrpdeGUcIhCiS47/poEUIm+p+VcpDqjHY hADokFVBMEUJhAQKmV9Cfuu9UJ6wtsUy+bcIYFgn8O8NWHqKz0GaPXOEjARMq+km X9G8ObGPZVAovor8F/P7ChLejjzjxUsm0Up9wuxG/62zROS209lib71n+C43R3JL 4ZUlp/I1Oc5iSJX4bEcFUKG1QYjO6w4PvShdco4snfiwYx4Mg+/erWdRyE8nVypT 38Aa32HSYDWsTZGUGq8Q76xgL7j+UB/wpR2JT107Kg2CSxh5y81oh19qJfxGRbs2 dYuqU/36QEXEQXwEVNsfJmdXWxfhvT38hFIZi5nf+zYvEk5lUrkD+/8j7GkRtol4 O/BzE8xj3zKz8M47P5NbvR/1ilQ6/cOpGsdh+mfT1OpoGVumJMjh7q8RJA4WEdn1 aYnKJFzzeZdtGf77/Azflqoec1nddBGeweajOasDFGoJgoB5kS0q6ZfO4Zh/oUNt bo+e7bx1HlWUDXycHNP0Mu/tnUBO6VR+yBBohmZHqXuyjPz70yp46i9lNjTZeb44 +sMSGgj+0MNWjmlM4RtihqMX1WOJx66hVmwTXHbBOvkQc9ygALk= =h2zo -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6348-1] gsasl security update Next by Date: [SECURITY] [DSA 6350-1] firefox-esr security update Previous by thread: [SECURITY] [DSA 6348-1] gsasl security update Next by thread: [SECURITY] [DSA 6350-1] firefox-esr security update Index(es): Date Thread

Share this article