Severity
6.5MEDIUM
EPSS
0.9%
top 24.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 4

Description

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

NVDlibrdf/raptor< 2.0.7
NVDapache/openoffice3.3.0, 3.4.0+1

Also affects: Debian Linux 6.0, Fedora 16, 17, Enterprise Linux 6.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-28qp-8c7m-wc33: Redland Raptor (aka libraptor) before 22022-05-04
CVEList
CVE-2012-0037: Redland Raptor (aka libraptor) before 22012-06-17

📋Vendor Advisories

3
Ubuntu
Raptor vulnerability2013-07-08
Ubuntu
Raptor vulnerability2012-06-18
Red Hat
raptor: XML External Entity (XXE) attack via RDF files2012-03-22

💬Community

4
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [epel-5]2012-03-22
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-16]2012-03-22
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack by processing certain RDF files [fedora-all]2012-03-22
Bugzilla
CVE-2012-0037 raptor: XML External Entity (XXE) attack via RDF files2012-02-16
CVE-2012-0037 (MEDIUM CVSS 6.5) | Redland Raptor (aka libraptor) befo | cvebase.io