MEDIUM · 6.5

CVE-2012-0037

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read ...

Vulnerability Description

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LibrdfRaptor< 2.0.7
LibreofficeLibreoffice< 3.4.6
ApacheOpenoffice3.3.0
FedoraprojectFedora16
RedhatGluster Storage Server For On-Premise2.0
RedhatStorage2.0
RedhatStorage For Public Cloud2.0
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus6.2
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus6.2
RedhatEnterprise Linux Workstation5.0
DebianDebian Linux6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0037?

CVE-2012-0037 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read ...

How severe is CVE-2012-0037?

CVE-2012-0037 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0037?

Check the references section above for vendor advisories and patch information. Affected products include: Librdf Raptor, Libreoffice Libreoffice, Apache Openoffice, Fedoraproject Fedora, Redhat Gluster Storage Server For On-Premise.