CVE-2019-13032

NameCVE-2019-13032
DescriptionAn issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs931246

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
flightcrew (PTS)stretch0.7.2+dfsg-9vulnerable
buster0.7.2+dfsg-13vulnerable
bullseye, sid0.9.3+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
flightcrewsource(unstable)0.7.2+dfsg-14unimportant931246

Notes

https://github.com/Sigil-Ebook/flightcrew/issues/53
https://github.com/Sigil-Ebook/flightcrew/commit/c75c100218ed5c0e7652947051e28b54a75212ae
https://github.com/Sigil-Ebook/flightcrew/commit/b4f4a70f604ddcb4e8e343aa0e690764fc46d780
Negligible security impact

Search for package or bug name: Reporting problems