Lucene search

K
cve[email protected]CVE-2012-0037
HistoryJun 17, 2012 - 3:41 a.m.

CVE-2012-0037

2012-06-1703:41:40
CWE-611
web.nvd.nist.gov
40
4
cve-2012-0037
redland raptor
libraptor
openoffice
libreoffice
xxe
remote attackers
arbitrary files
xml
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Affected configurations

NVD
Node
librdfraptorRange<2.0.7
Node
libreofficelibreofficeRange<3.4.6
OR
libreofficelibreofficeMatch3.5.0
Node
apacheopenofficeMatch3.3.0
OR
apacheopenofficeMatch3.4.0beta
Node
fedoraprojectfedoraMatch16
OR
fedoraprojectfedoraMatch17
Node
redhatgluster_storage_server_for_on-premiseMatch2.0
OR
redhatstorageMatch2.0
OR
redhatstorage_for_public_cloudMatch2.0
OR
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_eusMatch6.2
OR
redhatenterprise_linux_serverMatch5.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_server_ausMatch6.2
OR
redhatenterprise_linux_workstationMatch5.0
OR
redhatenterprise_linux_workstationMatch6.0
Node
debiandebian_linuxMatch6.0
CPENameOperatorVersion
librdf:raptorlibrdf raptorlt2.0.7

References

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%