Kovid Goyal · Calibre · CVE-2016-10187
**Name of the Vulnerable Software and Affected Versions**
calibre versions prior to 2.75
ALT Linux (affected versions not specified)
**Description**
The issue allows remote attackers to read arbitrary files via a crafted epub file with JavaScript. There is also a mention of a vulnerability in the ALT Linux package, but details are not provided.
**Recommendations**
For calibre versions prior to 2.75, update to version 2.75 or later to resolve the issue.
For ALT Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.