Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25005
HistoryApr 10, 2020 - 1:12 a.m.

XML External Entity Expansion

2020-04-1001:12:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.004 Low

EPSS

Percentile

74.8%

openoffice.org is vulnerable to XML External Entity expansion. If OpenOffice.org were to open a specially-crafted file (such as an OpenDocument Format or OpenDocument Presentation file), it could possibly allow a remote attacker to obtain a copy of an arbitrary local file that the user running OpenOffice.org had access to. A bug in the way Raptor handled external entities could cause OpenOffice.org to crash or, possibly, execute arbitrary code with the privileges of the user running OpenOffice.org.

References