Bug 791296 (CVE-2012-0037)
Summary: | CVE-2012-0037 raptor: XML External Entity (XXE) attack via RDF files | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | caolanm, jskarvad, mstahl, security-response-team, uwog, veillard |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-07-18 10:44:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 804494, 804495, 804496, 804498, 805938, 805941, 805944 | ||
Bug Blocks: | 796333, 796335, 796336 |
Description
Jan Lieskovsky
2012-02-16 16:46:58 UTC
This issue affects the version of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5. -- This issue affects the version of the raptor package, as shipped with Red Hat Enterprise Linux 6. -- This issue affects the versions of the raptor package, as shipped with Fedora EPEL 5. -- This issue affects the versions of the raptor package, as shipped with Fedora release of 15 and 16. -- This issue affects the version of the raptor2 package, as shipped with Fedora release of 16. Preliminary embargo date for public disclosure of this issue has been set up to Thursday, March 22, 2012 at 12:00 UTC time. Public now via: http://www.openoffice.org/security/cves/CVE-2012-0037.html http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/ http://www.libreoffice.org/advisories/CVE-2012-0037/ Created raptor tracking bugs for this issue Affects: epel-5 [bug 805938] Created raptor tracking bugs for this issue Affects: fedora-all [bug 805941] Created raptor2 tracking bugs for this issue Affects: fedora-16 [bug 805944] This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:0410 https://rhn.redhat.com/errata/RHSA-2012-0410.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:0411 https://rhn.redhat.com/errata/RHSA-2012-0411.html |