CVE-2013-5648: Id Id-Software
Medium severity, CVSS 6.8. EPSS: 2.1% chance of exploitation in the next 30 days.
Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.
Affected products
Published 2013-08-29. Last modified 2026-06-16.