6.5

CVE-2012-0037

Exploit

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Data is provided by the National Vulnerability Database (NVD)
LibrdfRaptor Version < 2.0.7
LibreofficeLibreoffice Version < 3.4.6
LibreofficeLibreoffice Version3.5.0
ApacheOpenoffice Version3.3.0
ApacheOpenoffice Version3.4.0 Updatebeta
FedoraprojectFedora Version16
FedoraprojectFedora Version17
RedhatStorage Version2.0
RedhatEnterprise Linux Eus Version6.2
DebianDebian Linux Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.663
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

http://secunia.com/advisories/48479
Vendor Advisory
Broken Link
http://secunia.com/advisories/48493
Vendor Advisory
Broken Link
http://secunia.com/advisories/48526
Vendor Advisory
Broken Link
http://secunia.com/advisories/48529
Vendor Advisory
Broken Link
http://secunia.com/advisories/48542
Vendor Advisory
Broken Link
http://www.securityfocus.com/bid/52681
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026837
Third Party Advisory
Broken Link
VDB Entry