CVE-2012-0037
raptor: XML External Entity (XXE) attack via RDF files
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
Redland Raptor (también conocido como libraptor) anterior a v2.0.7, utilizado por OpenOffice v3.3 y v3.4 Beta, LibreOffice anterior a v3.4.6 y v3.5.x anterior a v3.5.1, y otros productos, permite a atacantes remotos asistidos por el usuario leer archivos arbitrarios a través de una declaración de entidad externa (XXE) en xml y con referencia a un documento RDF.
Timothy D. Morgan discovered that Raptor would unconditionally load XML external entities. If a user were tricked into opening a specially crafted document in an application linked against Raptor, an attacker could possibly obtain access to arbitrary files on the user's system or potentially execute arbitrary code with the privileges of the user invoking the program.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-07 CVE Reserved
- 2012-06-17 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (33)
URL | Tag | Source |
---|---|---|
http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6 | Release Notes | |
http://librdf.org/raptor/RELEASE.html#rel2_0_7 | Release Notes | |
http://secunia.com/advisories/48494 | Broken Link | |
http://secunia.com/advisories/48649 | Broken Link | |
http://secunia.com/advisories/50692 | Broken Link | |
http://secunia.com/advisories/60799 | Broken Link | |
http://vsecurity.com/resources/advisory/20120324-1 | Broken Link | |
http://www.osvdb.org/80307 | Broken Link | |
http://www.securityfocus.com/bid/52681 | Broken Link | |
http://www.securitytracker.com/id?1026837 | Broken Link | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74235 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2012/03/27/4 | 2024-08-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Librdf Search vendor "Librdf" | Raptor Search vendor "Librdf" for product "Raptor" | < 2.0.7 Search vendor "Librdf" for product "Raptor" and version " < 2.0.7" | - |
Affected
| ||||||
Libreoffice Search vendor "Libreoffice" | Libreoffice Search vendor "Libreoffice" for product "Libreoffice" | < 3.4.6 Search vendor "Libreoffice" for product "Libreoffice" and version " < 3.4.6" | - |
Affected
| ||||||
Libreoffice Search vendor "Libreoffice" | Libreoffice Search vendor "Libreoffice" for product "Libreoffice" | 3.5.0 Search vendor "Libreoffice" for product "Libreoffice" and version "3.5.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Openoffice Search vendor "Apache" for product "Openoffice" | 3.3.0 Search vendor "Apache" for product "Openoffice" and version "3.3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Openoffice Search vendor "Apache" for product "Openoffice" | 3.4.0 Search vendor "Apache" for product "Openoffice" and version "3.4.0" | beta |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 16 Search vendor "Fedoraproject" for product "Fedora" and version "16" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 17 Search vendor "Fedoraproject" for product "Fedora" and version "17" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Gluster Storage Server For On-premise Search vendor "Redhat" for product "Gluster Storage Server For On-premise" | 2.0 Search vendor "Redhat" for product "Gluster Storage Server For On-premise" and version "2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Storage Search vendor "Redhat" for product "Storage" | 2.0 Search vendor "Redhat" for product "Storage" and version "2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Storage For Public Cloud Search vendor "Redhat" for product "Storage For Public Cloud" | 2.0 Search vendor "Redhat" for product "Storage For Public Cloud" and version "2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 5.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 6.2 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "6.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 5.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 6.2 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "6.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 5.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
|