CVE-2013-5648: Id Id-Software

Medium severity, CVSS 6.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

Affected products

  • Id Id-Software: version 3.7 only; version 3.7.1 only
  • Id Libdigidoc: version 3.6.0.0 only

Published 2013-08-29. Last modified 2026-06-16.