Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28qp-8c7m-wc33

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Ссылки

EPSS

Процентиль: 66%
0.00534
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-611

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 13 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

redhat
больше 13 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
nvd
около 13 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
debian
около 13 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 ...

oracle-oval
больше 13 лет назад

ELSA-2012-0410: raptor security update (IMPORTANT)

EPSS

Процентиль: 66%
0.00534
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-611