CVE-2013-5648
Publication date 29 August 2013
Last updated 24 July 2024
Ubuntu priority
Description
Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libdigidoc | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
References
Other references
- http://svnweb.mageia.org/packages/updates/3/libdigidoc/current/SOURCES/libdigidoc-3.6.0.0-security-fix-DataFile-name-tag.patch?revision=472660&view=markup
- https://bugzilla.redhat.com/show_bug.cgi?id=1002299
- https://bugs.mageia.org/show_bug.cgi?id=11100
- http://www.id.ee/?lang=en&id=34283#3_7_2
- https://www.cve.org/CVERecord?id=CVE-2013-5648