Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.
https://bugzilla.redhat.com/show_bug.cgi?id=1002299
https://bugs.mageia.org/show_bug.cgi?id=11100