USN-4085-1: Sigil vulnerability

1 August 2019

Sigil vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 19.04
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS


Sigil could be made to overwrite files.

Software Description

  • sigil - multi-platform ebook editor


Mike Salvatore discovered that Sigil mishandled certain malformed EPUB files. An attacker could use this vulnerability to write arbitrary files to the filesystem.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
sigil - 0.9.13+dfsg-1ubuntu0.1
sigil-data - 0.9.13+dfsg-1ubuntu0.1
Ubuntu 18.04 LTS
sigil - 0.9.9+dfsg-1ubuntu0.1~esm1
sigil-data - 0.9.9+dfsg-1ubuntu0.1~esm1
Ubuntu 16.04 LTS
sigil - 0.9.5+dfsg-0ubuntu1+esm1
sigil-data - 0.9.5+dfsg-0ubuntu1+esm1

To update your system, please follow these instructions:

In general, a standard system update will make all the necessary changes.