Vulnerability Description
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sigil-Ebook | Sigil | < 0.9.16 |
| Flightcrew Project | Flightcrew | >= 0.9.2 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- https://github.com/Sigil-Ebook/Sigil/commit/04e2f280cc4a0766bedcc7b9eb56449ceeccPatchThird Party Advisory
- https://github.com/Sigil-Ebook/Sigil/commit/0979ba8d10c96ebca330715bfd4494ea0e01PatchThird Party Advisory
- https://github.com/Sigil-Ebook/Sigil/commit/369eebe936e4a8c83cc54662a3412ce8bef1PatchThird Party Advisory
- https://github.com/Sigil-Ebook/Sigil/compare/ea7f27d...5b867e5Third Party Advisory
- https://github.com/Sigil-Ebook/Sigil/releases/tag/0.9.16Release NotesThird Party Advisory
- https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505967936Third Party Advisory
- https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505997355Third Party Advisory
- https://salvatoresecurity.com/zip-slip-in-sigil-cve-2019-14452/
- https://usn.ubuntu.com/4085-1/Third Party Advisory
- https://github.com/Sigil-Ebook/Sigil/commit/04e2f280cc4a0766bedcc7b9eb56449ceeccPatchThird Party Advisory
- https://github.com/Sigil-Ebook/Sigil/commit/0979ba8d10c96ebca330715bfd4494ea0e01PatchThird Party Advisory
- https://github.com/Sigil-Ebook/Sigil/commit/369eebe936e4a8c83cc54662a3412ce8bef1PatchThird Party Advisory
- https://github.com/Sigil-Ebook/Sigil/compare/ea7f27d...5b867e5Third Party Advisory
- https://github.com/Sigil-Ebook/Sigil/releases/tag/0.9.16Release NotesThird Party Advisory
- https://github.com/Sigil-Ebook/flightcrew/issues/52#issuecomment-505967936Third Party Advisory
FAQ
What is CVE-2019-14452?
CVE-2019-14452 is a vulnerability with a CVSS score of 7.5 (HIGH). Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
How severe is CVE-2019-14452?
CVE-2019-14452 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14452?
Check the references section above for vendor advisories and patch information. Affected products include: Sigil-Ebook Sigil, Flightcrew Project Flightcrew, Canonical Ubuntu Linux.