CVE-2019-14452: Path Traversal
Last updated 25 August 2025
Other sources
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14452?
CVE-2019-14452 is classified as a moderate severity vulnerability due to the potential for directory traversal exploits.
How do I fix CVE-2019-14452?
To fix CVE-2019-14452, upgrade Sigil to version 0.9.16 or later, which addresses the directory traversal vulnerability.
What systems are affected by CVE-2019-14452?
CVE-2019-14452 affects all Sigil versions prior to 0.9.16 across various Linux distributions, including Ubuntu and Debian.
What type of vulnerability is CVE-2019-14452?
CVE-2019-14452 is a directory traversal vulnerability that allows attackers to write arbitrary files.
Can CVE-2019-14452 be exploited remotely?
Yes, CVE-2019-14452 can be exploited remotely if an attacker can upload a malicious ZIP archive to an affected system.