← Back

CVE-2013-5648

nvd nist
Published: Aug 29, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

Affected (3)

2 products
Id Software
Libdigidoc
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Id
Version 3.7.1
Version 3.7
Version 3.6.0.0

Timeline

No history available yet.