USN-4085-1: Sigil vulnerability

1 August 2019

Sigil vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 19.04
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS

Summary

Sigil could be made to overwrite files.

Software Description

  • sigil - multi-platform ebook editor

Details

Mike Salvatore discovered that Sigil mishandled certain malformed EPUB files. An attacker could use this vulnerability to write arbitrary files to the filesystem.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
sigil - 0.9.13+dfsg-1ubuntu0.1
sigil-data - 0.9.13+dfsg-1ubuntu0.1
Ubuntu 18.04 LTS
sigil - 0.9.9+dfsg-1ubuntu0.1~esm1
sigil-data - 0.9.9+dfsg-1ubuntu0.1~esm1
Ubuntu 16.04 LTS
sigil - 0.9.5+dfsg-0ubuntu1+esm1
sigil-data - 0.9.5+dfsg-0ubuntu1+esm1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References