CVE-2019-13032

An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.

Date published : 2019-06-28

https://github.com/Sigil-Ebook/flightcrew/issues/53

Fun with Fuzzers: How I Discovered Three Vulnerabilities (Part 1 of 3)