CVE-2019-14452

Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
References
Link Resource
https://github.com/Sigil-Ebook/Sigil/commit/04e2f280cc4a0766bedcc7b9eb56449ceecc2ad4 Patch Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/commit/0979ba8d10c96ebca330715bfd4494ea0e019a8f Patch Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/commit/369eebe936e4a8c83cc54662a3412ce8bef189e4 Patch Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/compare/ea7f27d...5b867e5 Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/releases/tag/0.9.16 Release Notes Third Party Advisory
https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505967936 Third Party Advisory
https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505997355 Third Party Advisory
https://salvatoresecurity.com/zip-slip-in-sigil-cve-2019-14452/
https://usn.ubuntu.com/4085-1/ Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/commit/04e2f280cc4a0766bedcc7b9eb56449ceecc2ad4 Patch Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/commit/0979ba8d10c96ebca330715bfd4494ea0e019a8f Patch Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/commit/369eebe936e4a8c83cc54662a3412ce8bef189e4 Patch Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/compare/ea7f27d...5b867e5 Third Party Advisory
https://github.com/Sigil-Ebook/Sigil/releases/tag/0.9.16 Release Notes Third Party Advisory
https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505967936 Third Party Advisory
https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505997355 Third Party Advisory
https://salvatoresecurity.com/zip-slip-in-sigil-cve-2019-14452/
https://usn.ubuntu.com/4085-1/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sigil-ebook:sigil:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:flightcrew_project:flightcrew:*:*:*:*:*:sigil:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

History

21 Nov 2024, 04:26

Type Values Removed Values Added
References () https://github.com/Sigil-Ebook/Sigil/commit/04e2f280cc4a0766bedcc7b9eb56449ceecc2ad4 - Patch, Third Party Advisory () https://github.com/Sigil-Ebook/Sigil/commit/04e2f280cc4a0766bedcc7b9eb56449ceecc2ad4 - Patch, Third Party Advisory
References () https://github.com/Sigil-Ebook/Sigil/commit/0979ba8d10c96ebca330715bfd4494ea0e019a8f - Patch, Third Party Advisory () https://github.com/Sigil-Ebook/Sigil/commit/0979ba8d10c96ebca330715bfd4494ea0e019a8f - Patch, Third Party Advisory
References () https://github.com/Sigil-Ebook/Sigil/commit/369eebe936e4a8c83cc54662a3412ce8bef189e4 - Patch, Third Party Advisory () https://github.com/Sigil-Ebook/Sigil/commit/369eebe936e4a8c83cc54662a3412ce8bef189e4 - Patch, Third Party Advisory
References () https://github.com/Sigil-Ebook/Sigil/compare/ea7f27d...5b867e5 - Third Party Advisory () https://github.com/Sigil-Ebook/Sigil/compare/ea7f27d...5b867e5 - Third Party Advisory
References () https://github.com/Sigil-Ebook/Sigil/releases/tag/0.9.16 - Release Notes, Third Party Advisory () https://github.com/Sigil-Ebook/Sigil/releases/tag/0.9.16 - Release Notes, Third Party Advisory
References () https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505967936 - Third Party Advisory () https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505967936 - Third Party Advisory
References () https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505997355 - Third Party Advisory () https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505997355 - Third Party Advisory
References () https://salvatoresecurity.com/zip-slip-in-sigil-cve-2019-14452/ - () https://salvatoresecurity.com/zip-slip-in-sigil-cve-2019-14452/ -
References () https://usn.ubuntu.com/4085-1/ - Third Party Advisory () https://usn.ubuntu.com/4085-1/ - Third Party Advisory

Information

Published : 2019-07-31 02:15

Updated : 2024-11-21 04:26


NVD link : CVE-2019-14452

Mitre link : CVE-2019-14452

CVE.ORG link : CVE-2019-14452


JSON object : View

Products Affected

flightcrew_project

  • flightcrew

canonical

  • ubuntu_linux

sigil-ebook

  • sigil
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')