Format: 1.8 Date: Wed, 31 Jul 2019 09:19:02 -0400 Source: sigil Binary: sigil Architecture: arm64 Version: 0.9.13+dfsg-1ubuntu0.1 Distribution: disco Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Mike Salvatore Description: sigil - multi-platform ebook editor Changes: sigil (0.9.13+dfsg-1ubuntu0.1) disco-security; urgency=medium . * SECURITY UPDATE: Zip Slip directory traversal when processing a crafted EPUB file - debian/patches/CVE-2019-14452-1.patch: do not allow zip files to have upward relative path sections. - debian/patches/CVE-2019-14452-2.patch: further harden against malicious epubs and produce error message. - debian/patches/CVE-2019-14452-3.patch: harden plugin unzipping to zip-slip attacks. - CVE-2019-14452 Checksums-Sha1: a512f538c9d31edbcbd9834fe07c584a6f257703 18460588 sigil-dbgsym_0.9.13+dfsg-1ubuntu0.1_arm64.ddeb d15558f6bf36bae360013feb90e59495e7ef0f81 13194 sigil_0.9.13+dfsg-1ubuntu0.1_arm64.buildinfo a1a603c1ae93f86c03a1392004a45b48236278be 1757876 sigil_0.9.13+dfsg-1ubuntu0.1_arm64.deb Checksums-Sha256: 784ae7b6af78806dfe7c4ea8020e10c19349a9508ff489c2f5f0ac7a87fd9455 18460588 sigil-dbgsym_0.9.13+dfsg-1ubuntu0.1_arm64.ddeb 225649a0ddc253e7322e68490fea2a403dc5303e166bf481a745eda519527952 13194 sigil_0.9.13+dfsg-1ubuntu0.1_arm64.buildinfo e4575a0d585a14c38e202a7ca76357ac94a684c6a8957e33fe7db9bcacbb025e 1757876 sigil_0.9.13+dfsg-1ubuntu0.1_arm64.deb Files: 9335ce563865db32d395f6b20c88c776 18460588 debug optional sigil-dbgsym_0.9.13+dfsg-1ubuntu0.1_arm64.ddeb 29f30deb9d6d43263d1404e2852d5fb8 13194 editors optional sigil_0.9.13+dfsg-1ubuntu0.1_arm64.buildinfo c9186d55af72db5d57f7a3c383dd645a 1757876 editors optional sigil_0.9.13+dfsg-1ubuntu0.1_arm64.deb Original-Maintainer: Mattia Rizzolo