Debian LTS: DLA-1204-1: evince security update
Summary
A specially-crafted embedded DVI filename could be exploited to run
commands as the current user when "printing" to PDF.
For Debian 7 "Wheezy", this issue has been fixed in evince version
3.4.0-3.1+deb7u2.
We recommend that you upgrade your evince packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-