CVE-2019-13032
published 2019-06-28CVE-2019-13032: An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments()…
PriorityP417medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.01%
59.7th percentile
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | flightcrew | < flightcrew 0.7.2+dfsg-14 (bookworm) | flightcrew 0.7.2+dfsg-14 (bookworm) |
| flightcrew_project | flightcrew | <= 0.9.2 | — |
| flightcrew_project | flightcrew | >= 0 < 0.7.2+dfsg-14 | 0.7.2+dfsg-14 |
| flightcrew_project | flightcrew | >= 0 < 0.7.2+dfsg-14 | 0.7.2+dfsg-14 |
| flightcrew_project | flightcrew | >= 0 < 0.7.2+dfsg-14 | 0.7.2+dfsg-14 |
| flightcrew_project | flightcrew | >= 0 < 0.7.2+dfsg-14 | 0.7.2+dfsg-14 |
| flightcrew_project | flightcrew | >= 0 < 0.7.2+dfsg-6ubuntu0.1 | 0.7.2+dfsg-6ubuntu0.1 |
| flightcrew_project | flightcrew | >= 0 < 0.7.2+dfsg-10ubuntu0.1 | 0.7.2+dfsg-10ubuntu0.1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qg8h-9c83-r4h2: An issue was discovered in FlightCrew v0
ghsa_unreviewed·2022-05-24
CVE-2019-13032 [MEDIUM] CWE-476 GHSA-qg8h-9c83-r4h2: An issue was discovered in FlightCrew v0
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
OSV
flightcrew vulnerabilities
osv·2019-07-15·CVSS 5.5
CVE-2019-13032 [MEDIUM] flightcrew vulnerabilities
flightcrew vulnerabilities
Mike Salvatore discovered that FlightCrew improperly handled certain
malformed EPUB files. An attacker could potentially use this vulnerability
to cause a denial of service. (CVE-2019-13032)
Mike Salvatore discovered that FlightCrew mishandled certain malformed EPUB
files. An attacker could use this vulnerability to write arbitrary files to
the filesystem. (CVE-2019-13241)
Mike Salvatore discovered that the version of Zipios included in FlightCrew
mishandled certain malformed ZIP files. An attacker could use this vulnerability
to cause a denial of service or consume system resources. (CVE-2019-13453)
OSV
CVE-2019-13032: An issue was discovered in FlightCrew v0
osv·2019-06-28·CVSS 5.5
CVE-2019-13032 [MEDIUM] CVE-2019-13032: An issue was discovered in FlightCrew v0
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
Ubuntu
flightcrew vulnerabilities
vendor_ubuntu·2019-07-15·CVSS 5.5
CVE-2019-13032 [MEDIUM] flightcrew vulnerabilities
Title: flightcrew vulnerabilities
Summary: Several security issues were fixed in FlightCrew.
Mike Salvatore discovered that FlightCrew improperly handled certain
malformed EPUB files. An attacker could potentially use this vulnerability
to cause a denial of service. (CVE-2019-13032)
Mike Salvatore discovered that FlightCrew mishandled certain malformed EPUB
files. An attacker could use this vulnerability to write arbitrary files to
the filesystem. (CVE-2019-13241)
Mike Salvatore discovered that the version of Zipios included in FlightCrew
mishandled certain malformed ZIP files. An attacker could use this vulnerability
to cause a denial of service or consume system resources. (CVE-2019-13453)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-13032: flightcrew - An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer derefer...
vendor_debian·2019·CVSS 5.5
CVE-2019-13032 [MEDIUM] CVE-2019-13032: flightcrew - An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer derefer...
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
Scope: local
bookworm: resolved (fixed in 0.7.2+dfsg-14)
bullseye: resolved (fixed in 0.7.2+dfsg-14)
forky: resolved (fixed in 0.7.2+dfsg-14)
sid: resolved (fixed in 0.7.2+dfsg-14)
trixie: resolved (fixed in 0.7.2+dfsg-14)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13032 FlightCrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments [fedora-all]
bugzilla·2019-07-10·CVSS 5.5
CVE-2019-13032 [MEDIUM] CVE-2019-13032 FlightCrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments [fedora-all]
CVE-2019-13032 FlightCrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2019-13032 flightcrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments
bugzilla·2019-07-10·CVSS 5.5
CVE-2019-13032 [MEDIUM] CVE-2019-13032 flightcrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments
CVE-2019-13032 flightcrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
Reference:
https://github.com/Sigil-Ebook/flightcrew/issues/53
Discussion:
Created FlightCrew tracking bugs for this issue:
Affects: fedora-all [bug 1728499]
---
Created FlightCrew tracking bugs for this issue:
Affects: epel-7 [bug 1728500]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supporte
Bugzilla
CVE-2019-13032 FlightCrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments [epel-7]
bugzilla·2019-07-10·CVSS 5.5
CVE-2019-13032 [MEDIUM] CVE-2019-13032 FlightCrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments [epel-7]
CVE-2019-13032 FlightCrew: null-pointer dereference in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
https://github.com/Sigil-Ebook/flightcrew/issues/53https://salvatoresecurity.com/fun-with-fuzzers-or-how-i-discovered-three-vulnerabilities-part-1-of-3/https://usn.ubuntu.com/4055-1/https://github.com/Sigil-Ebook/flightcrew/issues/53https://salvatoresecurity.com/fun-with-fuzzers-or-how-i-discovered-three-vulnerabilities-part-1-of-3/https://usn.ubuntu.com/4055-1/
2019-06-28
Published