CVE-2026-104983 Linux Mint Xreader 路径遍历漏洞
影响攻击者可借特制附件路径将文件写出预期目录,导致任意文件写入
Linux Mint Xreader 4.6.9 及之前版本的 PDF 附件保存处理逻辑存在路径遍历问题。该漏洞位于 shell/ev-window.c 的 g_file_get_child 函数,攻击者可通过操纵 attachment 参数实现目录穿越。漏洞 PoC 已公开,可能被实际利用。
影响范围
Linux Mint Xreader 至 4.6.9 版本(含)受影响,更高版本是否修复暂无公开信息。
漏洞详情
漏洞类型为路径遍历(CWE-22)。程序在保存 PDF 附件时未对 attachment 参数中的 ../ 等路径穿越字符做充分过滤,直接拼接进 g_file_get_child 生成目标路径,导致文件可被写到预期目录之外。攻击者可远程投递恶意 PDF 触发该逻辑。
利用条件与风险
利用需诱导用户打开恶意 PDF 并触发附件保存操作,属于远程社会工程场景。PoC 已公开,实战中可能被用于覆盖或写入用户可写路径下的文件,风险中等。
修复建议
官方尚未发布明确修复版本,维护者以 EPUB 支持已移除为由关闭该问题,但代码分析认为该判断可能有误。建议关注 Linux Mint/Xreader 后续更新,或在修复前避免打开来源不明的 PDF 附件。
A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipulation of the argument attachment leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. One of the project maintainers closed this issue as “completed”, because “EPUB support was removed from Xreader and reimplemented in Xepub”. Code analysis indicates that this might be a misunderstanding of the situation.