Document viewer
Go to file
RHEL Packaging Agent 22fac4d714 Fix CVE-2026-46529: command injection via crafted document links
Backport upstream commit 970c219e from evince to fix
CVE-2026-46529. The patch quotes string arguments (page
labels, named destinations, and search strings) passed to
ev_spawn when spawning a new Evince instance, preventing
untrusted values from being interpreted as unintended flags.

CVE: CVE-2026-46529
Upstream patches:
 - 970c219e86.patch
Resolves: RHEL-184039

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-06-16 12:28:40 +00:00
.gitignore Import rpm: c8s 2023-02-27 12:55:29 -05:00
0001-Resolves-deb-762530-rhbz-1061177-add-man-pages.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
0001-Revert-Bump-poppler-requirements-to-0.33.0.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.21.4-NPNVToolKit.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.2-covscan.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.2-TIFFReadRGBAImageOriented.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-annotations-a11y-names.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-application-id.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-containing-folder.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-CVE-2026-46529.patch Fix CVE-2026-46529: command injection via crafted document links 2026-06-16 12:28:40 +00:00
evince-3.28.4-handle-clicks-in-forms.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-move-annotations.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-reset-form-action.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-reset-form-translations.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince-3.28.4-Show-password-dialog-again.patch Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00
evince.spec Fix CVE-2026-46529: command injection via crafted document links 2026-06-16 12:28:40 +00:00
gating.yaml Bring gating.yaml over from Brew dist-git 2023-03-10 10:35:59 -08:00
sources Auto sync2gitlab import of evince-3.28.4-16.el8.src.rpm 2022-05-26 06:48:36 -04:00