{"id":"MGASA-2026-0209","summary":"Updated evince, atril & xreader packages fix security vulnerability","details":"Evince/Atril/Xreader command injection. (CVE-2026-46529)\n","modified":"2026-06-15T16:00:05.360996993Z","published":"2026-06-15T15:56:35Z","upstream":["CVE-2026-46529"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0209.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35553"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/05/19/34"}],"affected":[{"package":{"name":"evince","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/evince?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"44.2-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0209.json"}},{"package":{"name":"atril","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/atril?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.1-1.2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0209.json"}},{"package":{"name":"xreader","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/xreader?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.0-2.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0209.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}