CVE-2012-0037
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 13.68% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- librdf/raptor · libreoffice/libreoffice · apache/openoffice · fedoraproject/fedora · redhat/gluster storage server for on-premise · redhat/storage · redhat/storage for public cloud · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · debian/debian linux
- Source
- secalert@redhat.com
References
- http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/Release Notes
- http://librdf.org/raptor/RELEASE.html#rel2_0_7Release Notes
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077708.htmlMailing List
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078242.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2012-0410.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0411.htmlThird Party Advisory
- http://secunia.com/advisories/48479Broken Link, Vendor Advisory
- http://secunia.com/advisories/48493Broken Link, Vendor Advisory
- http://secunia.com/advisories/48494Broken Link
- http://secunia.com/advisories/48526Broken Link, Vendor Advisory
- http://secunia.com/advisories/48529Broken Link, Vendor Advisory
- http://secunia.com/advisories/48542Broken Link, Vendor Advisory
- http://secunia.com/advisories/48649Broken Link
- http://secunia.com/advisories/50692Broken Link
- http://secunia.com/advisories/60799Broken Link
- http://security.gentoo.org/glsa/glsa-201209-05.xmlThird Party Advisory
- http://vsecurity.com/resources/advisory/20120324-1/Broken Link
- http://www.debian.org/security/2012/dsa-2438Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlThird Party Advisory
- http://www.libreoffice.org/advisories/CVE-2012-0037/Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:061Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:062Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:063Broken Link
- http://www.openoffice.org/security/cves/CVE-2012-0037.htmlMitigation, Patch
- http://www.openwall.com/lists/oss-security/2012/03/27/4Exploit, Mailing List
- http://www.osvdb.org/80307Broken Link
- http://www.securityfocus.com/bid/52681Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026837Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74235Third Party Advisory, VDB Entry
- https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.