The updated packages fix security vulnerabilities: An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to . MGASA-2019-0396 - Updated flightcrew packages fix security vulnerabilities Publication date: 19 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0396.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13032, CVE-2019-13241 The updated packages fix security vulnerabilities: An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library. (CVE-2019-13032) FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. (CVE-2019-13241) References: - https://bugs.mageia.org/show_bug.cgi?id=25281 - https://ubuntu.com/security/notices/USN-4055-1 - https://www.cve.org/CVERecord?id=CVE-2019-13032 - https://www.cve.org/CVERecord?id=CVE-2019-13241 SRPMS: - 7/core/flightcrew-0.9.0-10.1.mga7 . MGASA-2019-0397: Revised FlightCrew modules mitigate potential security risks. Major updates strengthen overall system resilience.. FlightCrew Fixes, Security Update, Mageia 7 Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
- security fix for rhbz 1450956. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-607352ce5f 2017-05-25 19:36:11.634131 --------------------------------------------------------------------------------Name : FlightCrew Product : Fedora 24 Version : 0.9.1 Release : 7.fc24 URL : https://sigil-ebook.com/ Summary : EPUB validator Description : FlightCrew is a C++ epub validator. --------------------------------------------------------------------------------Update Information: - security fix for rhbz 1450956 --------------------------------------------------------------------------------References: [ 1 ] Bug #1450956 - FlightCrew: Insecure use of /tmp https://bugzilla.redhat.com/show_bug.cgi?id=1450956 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade FlightCrew' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.