Format: 1.8 Date: Wed, 31 Jul 2019 09:19:45 -0400 Source: sigil Binary: sigil sigil-data Architecture: arm64 Version: 0.9.5+dfsg-0ubuntu1+esm1 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Mike Salvatore Description: sigil - multi-platform ebook editor sigil-data - multi-platform ebook editor - data files Changes: sigil (0.9.5+dfsg-0ubuntu1+esm1) xenial-security; urgency=medium . * SECURITY UPDATE: Zip Slip directory traversal when processing a crafted EPUB file - debian/patches/CVE-2019-14452-1.patch: do not allow zip files to have upward relative path sections. - debian/patches/CVE-2019-14452-2.patch: further harden against malicious epubs and produce error message. - debian/patches/CVE-2019-14452-3.patch: harden plugin unzipping to zip-slip attacks. - CVE-2019-14452 Checksums-Sha1: 52da41fb1023c2525807b50566622219b6f49aae 12370340 sigil-dbgsym_0.9.5+dfsg-0ubuntu1+esm1_arm64.ddeb 182489399f150d8d0482643d081fcdc5bc48bf83 1539246 sigil_0.9.5+dfsg-0ubuntu1+esm1_arm64.deb Checksums-Sha256: affe9287f12a669f193e595ede4b853b256c132756f9c66cc7a73a1b30d7e795 12370340 sigil-dbgsym_0.9.5+dfsg-0ubuntu1+esm1_arm64.ddeb 9ede9aad60e20f585faaac9e46c0828d5b7d16597be9712c89f2015f4d3d5ab0 1539246 sigil_0.9.5+dfsg-0ubuntu1+esm1_arm64.deb Files: 3028bae9a3e11af676de16eb4f3cbc6a 12370340 editors extra sigil-dbgsym_0.9.5+dfsg-0ubuntu1+esm1_arm64.ddeb a97a357f5db5578b0c983a83047c22da 1539246 editors extra sigil_0.9.5+dfsg-0ubuntu1+esm1_arm64.deb Original-Maintainer: Mattia Rizzolo