CVE-2019-13032

NameCVE-2019-13032
DescriptionAn issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs931246

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
flightcrew (PTS)stretch0.7.2+dfsg-9+deb9u1fixed
buster0.7.2+dfsg-13+deb10u1fixed
bullseye, bookworm0.9.3+dfsg-1fixed
sid, trixie0.9.3+dfsg-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
flightcrewsourcestretch0.7.2+dfsg-9+deb9u1
flightcrewsourcebuster0.7.2+dfsg-13+deb10u1
flightcrewsource(unstable)0.7.2+dfsg-14unimportant931246

Notes

https://github.com/Sigil-Ebook/flightcrew/issues/53
https://github.com/Sigil-Ebook/flightcrew/commit/c75c100218ed5c0e7652947051e28b54a75212ae
https://github.com/Sigil-Ebook/flightcrew/commit/b4f4a70f604ddcb4e8e343aa0e690764fc46d780
Negligible security impact

Search for package or bug name: Reporting problems