FlightCrew Project FlightCrew 0.9.1 for Sigil

CPE Details

FlightCrew Project FlightCrew 0.9.1 for Sigil
0.9.1
2019-07-11
12h09 +00:00
2019-07-11
12h09 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:flightcrew_project:flightcrew:0.9.1:*:*:*:*:sigil:*:*

Informations

Vendor

flightcrew_project

Product

flightcrew

Version

0.9.1

Target Software

sigil

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-13241 2019-07-04 12h31 +00:00 FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
7.8
High
CVE-2019-13032 2019-06-28 20h56 +00:00 An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
5.5
Medium