CVE-2018-1000889
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration. This attack appears to be exploitable via the victim opening a specially crafted circuit file. This vulnerability appears to have been fixed in 2.14.4.
Logisim Evolution, en versiones 2.14.3 y anteriores, contiene una vulnerabilidad XEE (XML External Entity) en la funcionalidad de carga de archivos Circuit (loadXmlFrom en src/com/cburch/logisim/file/XmlReader.java) que puede resultar en la fuga de información y una posible ejecución remota de código, dependiendo de la configuración del sistema. El ataque parece ser explotable si una víctima abre un archivo circuit especialmente manipulado. La vulnerabilidad parece haber sido solucionada en la versión 2.14.4.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-27 CVE Reserved
- 2018-12-27 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.kvakil.me/posts/logisim | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/reds-heig/logisim-evolution/pull/139 | 2019-02-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Logisim-evolution Project Search vendor "Logisim-evolution Project" | Logisim-evolution Search vendor "Logisim-evolution Project" for product "Logisim-evolution" | <= 2.14.3 Search vendor "Logisim-evolution Project" for product "Logisim-evolution" and version " <= 2.14.3" | - |
Affected
|