Impact
The flaw in Linux Mint Xreader, located in the EPUB file handler, allows an attacker to manipulate the file path processed by g_strdup_printf. This leads to a directory traversal vulnerability that can be exploited remotely. An attacker could craft a malicious EPUB file that, when opened by Xreader, causes the application to resolve file paths outside the intended directory, potentially reading or overwriting arbitrary files. The published exploit demonstrates how this weakness can be triggered, raising the potential for unauthorized file access and data theft.
Affected Systems
Linux Mint Xreader versions up to and including 4.6.5 are affected. The 4.6.6 release contains the fix. The vulnerability is present in the EPUB File Handler component that was removed and reimplemented in Xepub.
Risk and Exploitability
The CVSS score for this issue is 5.3, indicating moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog. Because the attack vector is remote—an attacker can provide a crafted EPUB file—the exploitation process is straightforward. The publicly available exploit shows that a single malicious file is sufficient to trigger the path traversal, and no special privileges or additional conditions are required. Consequently, the vulnerability is considered moderately exploitable, especially on systems that routinely open or serve EPUB files to end users.
OpenCVE Enrichment