Lucene search

K
ubuntuUbuntuUSN-1480-1
HistoryJun 18, 2012 - 12:00 a.m.

Raptor vulnerability

2012-06-1800:00:00
ubuntu.com
35

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.8%

Releases

  • Ubuntu 12.04
  • Ubuntu 11.10
  • Ubuntu 11.04
  • Ubuntu 10.04

Packages

  • raptor - Raptor RDF parser and serializer library

Details

Timothy D. Morgan discovered that Raptor would unconditionally load XML
external entities. If a user were tricked into opening a specially crafted
document in an application linked against Raptor, an attacker could
possibly obtain access to arbitrary files on the user’s system or
potentially execute arbitrary code with the privileges of the user invoking
the program.

OSVersionArchitecturePackageVersionFilename
Ubuntu12.04noarchlibraptor1< 1.4.21-7ubuntu0.1UNKNOWN
Ubuntu12.04noarchlibraptor1-dbg< 1.4.21-7ubuntu0.1UNKNOWN
Ubuntu12.04noarchlibraptor1-dev< 1.4.21-7ubuntu0.1UNKNOWN
Ubuntu12.04noarchraptor-utils< 1.4.21-7ubuntu0.1UNKNOWN
Ubuntu11.10noarchlibraptor1< 1.4.21-5ubuntu0.1UNKNOWN
Ubuntu11.10noarchlibraptor1-dbg< 1.4.21-5ubuntu0.1UNKNOWN
Ubuntu11.10noarchlibraptor1-dev< 1.4.21-5ubuntu0.1UNKNOWN
Ubuntu11.10noarchraptor-utils< 1.4.21-5ubuntu0.1UNKNOWN
Ubuntu11.04noarchlibraptor1< 1.4.21-2ubuntu0.1UNKNOWN
Ubuntu11.04noarchlibraptor1-dbg< 1.4.21-2ubuntu0.1UNKNOWN
Rows per page:
1-10 of 161

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.8%