CVE-2012-0037
published 2012-06-17CVE-2012-0037: Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products…
PriorityP344medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
13.68%
96.1th percentile
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | — | — |
| apache | openoffice | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| librdf | raptor | < 2.0.7 | 2.0.7 |
| libreoffice | libreoffice | < 3.4.6 | 3.4.6 |
| libreoffice | libreoffice | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | gluster_storage_server_for_on-premise | — | — |
| redhat | storage | — | — |
| redhat | storage_for_public_cloud | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Raptor vulnerability
vendor_ubuntu·2013-07-08
CVE-2012-0037 Raptor vulnerability
Title: Raptor vulnerability
Summary: Applications using Raptor could be made to expose sensitive information or
run programs as your login if they opened a specially crafted file.
Timothy D. Morgan discovered that Raptor would unconditionally load XML
external entities. If a user were tricked into opening a specially crafted
document in an application linked against Raptor, an attacker could
possibly obtain access to arbitrary files on the user's system or
potentially execute arbitrary code with the privileges of the user invoking
the program.
Instructions: After a standard system update you need to restart any applications which
use Raptor, such as LibreOffice, to make all the necessary changes.
Ubuntu
Raptor vulnerability
vendor_ubuntu·2012-06-18
CVE-2012-0037 Raptor vulnerability
Title: Raptor vulnerability
Summary: Applications using Raptor could be made to expose sensitive information or
run programs as your login if they opened a specially crafted file.
Timothy D. Morgan discovered that Raptor would unconditionally load XML
external entities. If a user were tricked into opening a specially crafted
document in an application linked against Raptor, an attacker could
possibly obtain access to arbitrary files on the user's system or
potentially execute arbitrary code with the privileges of the user invoking
the program.
Instructions: After a standard system update you need to restart any applications which
use Raptor, such as OpenOffice.org or LibreOffice, to make all the
necessary changes.
Red Hat
raptor: XML External Entity (XXE) attack via RDF files
vendor_redhat·2012-03-22·CVSS 6.5
CVE-2012-0037 [MEDIUM] raptor: XML External Entity (XXE) attack via RDF files
raptor: XML External Entity (XXE) attack via RDF files
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
Package: openoffice.org (Red Hat Enterprise Linux 4) - Will not fix
GHSA
GHSA-28qp-8c7m-wc33: Redland Raptor (aka libraptor) before 2
ghsa_unreviewed·2022-05-04
CVE-2012-0037 [MEDIUM] CWE-200 GHSA-28qp-8c7m-wc33: Redland Raptor (aka libraptor) before 2
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [epel-5]
bugzilla·2012-03-22·CVSS 6.5
CVE-2012-0037 [MEDIUM] CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [epel-5]
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-16]
bugzilla·2012-03-22·CVSS 6.5
CVE-2012-0037 [MEDIUM] CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-16]
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/upda
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-all]
bugzilla·2012-03-22·CVSS 6.5
CVE-2012-0037 [MEDIUM] CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-all]
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/upd
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack via RDF files
bugzilla·2012-02-16·CVSS 6.5
CVE-2012-0037 [MEDIUM] CVE-2012-0037 raptor: XML External Entity (XXE) attack via RDF files
CVE-2012-0037 raptor: XML External Entity (XXE) attack via RDF files
A XML External Entity (XXE) flaw was found in the way raptor, an Resource Description Framework (RDF) parser toolkit, processed certain RDF/XML format based input files. If an attacker provided a specially-crafted RDF file, and tricked the local user into parsing it, it could lead to local file inclusion, or, potentially arbitrary code execution with the privileges of the user parsing the file (privileges of the "rapper" executable or privileges of an application, linked against the librdf library).
Acknowledgements:
Red Hat would like to thank Timothy D. Morgan of VSR for reporting this issue.
Discussion:
This issue affects the version of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5.
--
T
http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/http://librdf.org/raptor/RELEASE.html#rel2_0_7http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077708.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078242.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0410.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0411.htmlhttp://secunia.com/advisories/48479http://secunia.com/advisories/48493http://secunia.com/advisories/48494http://secunia.com/advisories/48526http://secunia.com/advisories/48529http://secunia.com/advisories/48542http://secunia.com/advisories/48649http://secunia.com/advisories/50692http://secunia.com/advisories/60799http://security.gentoo.org/glsa/glsa-201209-05.xmlhttp://vsecurity.com/resources/advisory/20120324-1/http://www.debian.org/security/2012/dsa-2438http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.libreoffice.org/advisories/CVE-2012-0037/http://www.mandriva.com/security/advisories?name=MDVSA-2012:061http://www.mandriva.com/security/advisories?name=MDVSA-2012:062http://www.mandriva.com/security/advisories?name=MDVSA-2012:063http://www.openoffice.org/security/cves/CVE-2012-0037.htmlhttp://www.openwall.com/lists/oss-security/2012/03/27/4http://www.osvdb.org/80307http://www.securityfocus.com/bid/52681http://www.securitytracker.com/id?1026837https://exchange.xforce.ibmcloud.com/vulnerabilities/74235https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0https://lists.apache.org/thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.apache.org%3Ehttp://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/http://librdf.org/raptor/RELEASE.html#rel2_0_7http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077708.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078242.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0410.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0411.htmlhttp://secunia.com/advisories/48479http://secunia.com/advisories/48493http://secunia.com/advisories/48494http://secunia.com/advisories/48526http://secunia.com/advisories/48529http://secunia.com/advisories/48542http://secunia.com/advisories/48649http://secunia.com/advisories/50692http://secunia.com/advisories/60799http://security.gentoo.org/glsa/glsa-201209-05.xmlhttp://vsecurity.com/resources/advisory/20120324-1/http://www.debian.org/security/2012/dsa-2438http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.libreoffice.org/advisories/CVE-2012-0037/http://www.mandriva.com/security/advisories?name=MDVSA-2012:061http://www.mandriva.com/security/advisories?name=MDVSA-2012:062http://www.mandriva.com/security/advisories?name=MDVSA-2012:063http://www.openoffice.org/security/cves/CVE-2012-0037.htmlhttp://www.openwall.com/lists/oss-security/2012/03/27/4http://www.osvdb.org/80307http://www.securityfocus.com/bid/52681http://www.securitytracker.com/id?1026837https://exchange.xforce.ibmcloud.com/vulnerabilities/74235https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0https://lists.apache.org/thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.apache.org%3E
2012-06-17
Published