CVE-2019-14452
31.07.2019, 02:15
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
| Vendor | Product | Version |
|---|---|---|
| sigil-ebook | sigil | 𝑥 < 0.9.16 |
| flightcrew_project | flightcrew | 0.9.2 ≤ |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References