Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-14940

Опубликовано: 23 июн. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tuxguitarfixed1.5.6+dfsg1-7package
tuxguitarignoredbookwormpackage
tuxguitarno-dsabullseyepackage
tuxguitarno-dsabusterpackage
tuxguitarno-dsastretchpackage
tuxguitarno-dsajessiepackage

Примечания

  • https://logicaltrust.net/blog/2020/06/tuxguitar.html

  • https://sourceforge.net/p/tuxguitar/bugs/126/

  • Fixed by: https://github.com/helge17/tuxguitar/commit/bcaa280e93b0d67dc6f903b6e23a051a7894ba0c

EPSS

Процентиль: 59%
0.00389
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

github
больше 3 лет назад

An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

EPSS

Процентиль: 59%
0.00389
Низкий