---
title: "CVE-2023-52076\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-52076?format=md
keywords: index, follow
---

# CVE-2023-52076

Publication date 25 January 2024

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2023-52076?format=md#impact-score)

Toggle side navigation

## Description

Atril Document Viewer is the default document reader of the MATE desktop
environment for Linux. A path traversal and arbitrary file write
vulnerability exists in versions of Atril prior to 1.26.2. This
vulnerability is capable of writing arbitrary files anywhere on the
filesystem to which the user opening a crafted document has access. The
only limitation is that this vulnerability cannot be exploited to overwrite
existing files, but that doesn't stop an attacker from achieving Remote
Command Execution on the target system. Version 1.26.2 of Atril contains a
patch for this vulnerability.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| atril | 24.04 LTS noble | Not affected |
| 23.10 mantic | Fixed 1.26.0-2ubuntu0.1 |
| 22.04 LTS jammy | Fixed 1.26.0-1ubuntu1.1 |
| 20.04 LTS focal | Fixed 1.24.0-1ubuntu0.1 |
| 18.04 LTS bionic | Fixed 1.20.1-2ubuntu2+esm1  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 1.12.2-1ubuntu0.3+esm1  Ubuntu Pro |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2023-52076?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| atril | * Upstream:   [e70b21c](https://github.com/mate-desktop/atril/commit/e70b21c815418a1e6ebedf6d8d31b8477c03ba50) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52076)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-52076)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-52076)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-52076)

### Related Ubuntu Security Notices (USN)

+ [USN-6808-1](https://usn.ubuntu.com/USN-6808-1)
+ Atril vulnerability
+ 5 June 2024

### Other references

* <https://github.com/mate-desktop/atril/security/advisories/GHSA-6mf6-mxpc-jc37>
* <https://github.com/mate-desktop/atril/commit/e70b21c815418a1e6ebedf6d8d31b8477c03ba50>
* <https://github.com/mate-desktop/atril/releases/tag/v1.26.2>
* <https://www.cve.org/CVERecord?id=CVE-2023-52076>
