Format: 1.8 Date: Wed, 31 Jul 2019 09:19:02 -0400 Source: sigil Binary: sigil Architecture: armhf Version: 0.9.13+dfsg-1ubuntu0.1 Distribution: disco Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Mike Salvatore Description: sigil - multi-platform ebook editor Changes: sigil (0.9.13+dfsg-1ubuntu0.1) disco-security; urgency=medium . * SECURITY UPDATE: Zip Slip directory traversal when processing a crafted EPUB file - debian/patches/CVE-2019-14452-1.patch: do not allow zip files to have upward relative path sections. - debian/patches/CVE-2019-14452-2.patch: further harden against malicious epubs and produce error message. - debian/patches/CVE-2019-14452-3.patch: harden plugin unzipping to zip-slip attacks. - CVE-2019-14452 Checksums-Sha1: 65628e0625753a48d25a2913ae1d97892977c085 18556280 sigil-dbgsym_0.9.13+dfsg-1ubuntu0.1_armhf.ddeb a1ed1283146fbd0838b9c2f62d56f9babb0b3b63 13281 sigil_0.9.13+dfsg-1ubuntu0.1_armhf.buildinfo b82d2767a4cccb357fc8489f373c0e0267d556b5 1697720 sigil_0.9.13+dfsg-1ubuntu0.1_armhf.deb Checksums-Sha256: 2c32752aebe0851ce6301ed476c63706c0b57a5e49f9c46008533fc528a3ab70 18556280 sigil-dbgsym_0.9.13+dfsg-1ubuntu0.1_armhf.ddeb 2ee0ef080a906ae1715a1e2f2ec48a2598a77c3c0d18f0bec3bcc90fa5f1dc25 13281 sigil_0.9.13+dfsg-1ubuntu0.1_armhf.buildinfo dcfb18c119101cc18199dbf24c81490c222a9c37a421779179016204b1c71485 1697720 sigil_0.9.13+dfsg-1ubuntu0.1_armhf.deb Files: 580852b97d69a87e97c44971fe19b265 18556280 debug optional sigil-dbgsym_0.9.13+dfsg-1ubuntu0.1_armhf.ddeb 282dad5e109456832b6826fa597d4885 13281 editors optional sigil_0.9.13+dfsg-1ubuntu0.1_armhf.buildinfo b48e209abf187a5cccbf25a72399acff 1697720 editors optional sigil_0.9.13+dfsg-1ubuntu0.1_armhf.deb Original-Maintainer: Mattia Rizzolo