CVE-2019-13241: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.

FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only; version 19.04 only
  • Flightcrew Project Flightcrew: up to and including 0.9.2

Published 2019-07-04. Last modified 2026-06-17.