MGASA-2019-0396

Source
https://advisories.mageia.org/MGASA-2019-0396.html
Import Source
https://advisories.mageia.org/MGASA-2019-0396.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0396
Related
Published
2019-12-19T13:44:26Z
Modified
2019-12-19T13:24:15Z
Summary
Updated flightcrew packages fix security vulnerabilities
Details

The updated packages fix security vulnerabilities:

An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library. (CVE-2019-13032)

FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. (CVE-2019-13241)

References
Credits

Affected packages

Mageia:7 / flightcrew

Package

Name
flightcrew
Purl
pkg:rpm/mageia/flightcrew?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.0-10.1.mga7

Ecosystem specific

{
    "section": "core"
}