VDB

GCVE-110-MAGEIA-2019-396

GCVE-110-MAGEIA-2019-396
Advisory Published
Vulnetix · Advisory published December 19, 2019
The updated packages fix security vulnerabilities: An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library. (CVE-2019-13032) FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. (CVE-2019-13241)

Affected Products

VendorProductVersionsPlatforms
Mageiaflightcrew0 (affected), 0.9.0-10.1.mga7 (unaffected)

Browse GCVE Records

74,585 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›