CVE-2012-0037
MEDIUMRedland Raptor < 2.0.7 - XML External Entity Injection via RDF Document
Title source: llmDescription
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
References (31)
Core 31
Core References
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/60799
Broken Link, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48526
Broken Link, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48479
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201209-05.xml
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48494
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1026837
Broken Link vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:061
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/52681
Mailing List vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078242.html
Broken Link, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48529
Broken Link vdb-entry
x_refsource_osvdb
http://www.osvdb.org/80307
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0410.html
Exploit, Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/27/4
Broken Link vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:062
Broken Link, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48542
Vendor Advisory x_refsource_confirm
http://www.libreoffice.org/advisories/CVE-2012-0037/
Broken Link x_refsource_misc
http://vsecurity.com/resources/advisory/20120324-1/
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/50692
Release Notes x_refsource_confirm
http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48649
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74235
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2012/dsa-2438
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0411.html
Broken Link, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48493
Mailing List vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077708.html
Broken Link vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:063
Mitigation, Patch x_refsource_confirm
http://www.openoffice.org/security/cves/CVE-2012-0037.html
Release Notes x_refsource_confirm
http://librdf.org/raptor/RELEASE.html#rel2_0_7
Patch x_refsource_confirm
https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0
Mailing List, Patch mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.apache.org%3E
Scores
CVSS v3
6.5
EPSS
0.1368
EPSS Percentile
96.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Details
CWE
CWE-611
Status
published
Products (19)
apache/openoffice
3.3.0
apache/openoffice
3.4.0 beta
debian/debian_linux
6.0
fedoraproject/fedora
16
fedoraproject/fedora
17
librdf/raptor
< 2.0.7
libreoffice/libreoffice
3.5.0
libreoffice/libreoffice
< 3.4.6
redhat/enterprise_linux_desktop
5.0
redhat/enterprise_linux_desktop
6.0
... and 9 more
Published
Jun 17, 2012
Tracked Since
Feb 18, 2026