CVE-2019-13241: Path Traversal
Published Jul 4, 2019
·Updated
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
Affected Software
6 affected componentsFixes available
debian/flightcrew
0.9.3+dfsg-10.9.3+dfsg-2.1
Flightcrew Project Flightcrew Sigil<=0.9.2
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Canonical Ubuntu Linux=19.04
Event History
Jul 4, 2019
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:16 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·10:51 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-13241?
CVE-2019-13241 is classified as a high severity vulnerability due to the potential for unauthorized file writing.
2
How do I fix CVE-2019-13241?
To mitigate CVE-2019-13241, update FlightCrew to version 0.9.3 or newer.
3
What are the affected versions for CVE-2019-13241?
CVE-2019-13241 affects FlightCrew versions up to and including 0.9.2.
4
Which operating systems are impacted by CVE-2019-13241?
CVE-2019-13241 impacts users on Debian and specific versions of Ubuntu including 16.04, 18.04, 18.10, and 19.04.
5
What type of vulnerability is CVE-2019-13241?
CVE-2019-13241 is a directory traversal vulnerability that allows attackers to write arbitrary files.