Format: 1.8 Date: Wed, 31 Jul 2019 09:19:23 -0400 Source: sigil Binary: sigil sigil-data Architecture: all amd64 Version: 0.9.9+dfsg-1ubuntu0.1~esm1 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Mike Salvatore Description: sigil - multi-platform ebook editor sigil-data - multi-platform ebook editor - data files Changes: sigil (0.9.9+dfsg-1ubuntu0.1~esm1) bionic-security; urgency=medium . * SECURITY UPDATE: Zip Slip directory traversal when processing a crafted EPUB file - debian/patches/CVE-2019-14452-1.patch: do not allow zip files to have upward relative path sections. - debian/patches/CVE-2019-14452-2.patch: further harden against malicious epubs and produce error message. - debian/patches/CVE-2019-14452-3.patch: harden plugin unzipping to zip-slip attacks. - CVE-2019-14452 Checksums-Sha1: 5a86c2068c38f8b793f14c8be2d54b1fc23f8d61 938392 sigil-data_0.9.9+dfsg-1ubuntu0.1~esm1_all.deb 674b4cd1c20733fdefe74d4ca13b8222415105c1 23999988 sigil-dbgsym_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.ddeb ba43954f3a0dbffd5661da03ddb54cda20c7fda4 14231 sigil_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.buildinfo 20d22623cbdb257f6842e27a2a29b875efcaa52d 1832836 sigil_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.deb Checksums-Sha256: 84abdc779f71e58fc24e25379bf254f45e1a1f76ef65f97e9b97584f5d3fc291 938392 sigil-data_0.9.9+dfsg-1ubuntu0.1~esm1_all.deb 947603a5d0609ddd5514a3905998267abb2752979b3b577af9c5496f02bb6eb0 23999988 sigil-dbgsym_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.ddeb 93cbd71569a61a14516747ec7242570b7208a9a73668c2e77180a224a6054250 14231 sigil_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.buildinfo 053d2f7f98f30212aeab3f5f41cfb3763f7d45719911664704a0d2bcf439cad7 1832836 sigil_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.deb Files: 4e0624776e533572f692dce720d631ca 938392 editors optional sigil-data_0.9.9+dfsg-1ubuntu0.1~esm1_all.deb c28bf099eec57d8a6b97117abc4e1875 23999988 debug optional sigil-dbgsym_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.ddeb 082567cf0b7975143dd7b50ed94b23cc 14231 editors optional sigil_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.buildinfo cab84f7cdaf2a9f5df624e591d2b8d3d 1832836 editors optional sigil_0.9.9+dfsg-1ubuntu0.1~esm1_amd64.deb Original-Maintainer: Mattia Rizzolo