6.5
CVE-2012-0037
- EPSS 13.68%
- Veröffentlicht 17.06.2012 03:41:40
- Zuletzt bearbeitet 16.06.2026 23:36:32
- Erkennungen
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libreoffice ≫ Libreoffice Version < 3.4.6
Libreoffice ≫ Libreoffice Version 3.5.0
Apache ≫ Openoffice Version 3.3.0
Apache ≫ Openoffice Version 3.4.0 Update beta
Fedoraproject ≫ Fedora Version 16
Fedoraproject ≫ Fedora Version 17
Redhat ≫ Gluster Storage Server For On-premise Version 2.0
Redhat ≫ Storage For Public Cloud Version 2.0
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.2
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 6.2
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Debian ≫ Debian Linux Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.68% | 0.96 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
http://secunia.com/advisories/60799
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
http://secunia.com/advisories/50692
http://security.gentoo.org/glsa/glsa-201209-05.xml
http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/
http://librdf.org/raptor/RELEASE.html#rel2_0_7
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077708.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078242.html
http://rhn.redhat.com/errata/RHSA-2012-0410.html
http://rhn.redhat.com/errata/RHSA-2012-0411.html
http://secunia.com/advisories/48479
http://secunia.com/advisories/48493
http://secunia.com/advisories/48494
http://secunia.com/advisories/48526
http://secunia.com/advisories/48529
http://secunia.com/advisories/48542
http://secunia.com/advisories/48649
http://vsecurity.com/resources/advisory/20120324-1/
http://www.debian.org/security/2012/dsa-2438
http://www.libreoffice.org/advisories/CVE-2012-0037/
http://www.mandriva.com/security/advisories?name=MDVSA-2012:061
http://www.mandriva.com/security/advisories?name=MDVSA-2012:062
http://www.mandriva.com/security/advisories?name=MDVSA-2012:063
http://www.openoffice.org/security/cves/CVE-2012-0037.html
http://www.openwall.com/lists/oss-security/2012/03/27/4
http://www.osvdb.org/80307
http://www.securityfocus.com/bid/52681
http://www.securitytracker.com/id?1026837
https://exchange.xforce.ibmcloud.com/vulnerabilities/74235
https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0
https://lists.apache.org/thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.apache.org%3E