Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0037

Опубликовано: 22 мар. 2012
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4openoffice.orgWill not fix
Red Hat Enterprise Linux 5openoffice.orgFixedRHSA-2012:041122.03.2012
Red Hat Enterprise Linux 6raptorFixedRHSA-2012:041022.03.2012

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=791296raptor: XML External Entity (XXE) attack via RDF files

EPSS

Процентиль: 76%
0.00897
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 14 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
nvd
почти 14 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
debian
почти 14 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 ...

CVSS3: 6.5
github
почти 4 года назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

oracle-oval
около 14 лет назад

ELSA-2012-0410: raptor security update (IMPORTANT)

EPSS

Процентиль: 76%
0.00897
Низкий

6.8 Medium

CVSS2