Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8315

Опубликовано: 20 апр. 2018
Источник: debian
EPSS Низкий

Описание

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apktoolfixed2.2.4-1package
apktoolno-dsastretchpackage

Примечания

  • Upstream bug with details is restricted

  • According to Red Hat only eclipse-andmore was affected but it was

  • never shipped with Debian. Apktool is affected though.

  • Possible fixes: https://github.com/iBotPeaches/Apktool/commit/f19317d87c316ed254aafa0a27eddd024e25ec6c

  • https://github.com/iBotPeaches/Apktool/commit/657a44f5938b072898a0de913c03760210e0f4ed

  • https://github.com/iBotPeaches/Apktool/commit/dbb144f9af5478c780e59c8b65036ae882595063

EPSS

Процентиль: 71%
0.00658
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

CVSS3: 5.6
redhat
около 8 лет назад

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

CVSS3: 7.5
nvd
почти 8 лет назад

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

CVSS3: 7.5
github
больше 3 лет назад

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

EPSS

Процентиль: 71%
0.00658
Низкий