Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1512827 - (CVE-2017-9096) CVE-2017-9096 itext: External entities not disabled
CVE-2017-9096 itext: External entities not disabled
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20171106,repor...
: Security
Depends On: 1512828
Blocks: 1512829
  Show dependency treegraph
 
Reported: 2017-11-14 03:45 EST by Andrej Nemec
Modified: 2018-04-22 19:55 EDT (History)
46 users (show)

See Also:
Fixed In Version: itext 5.5.12, itext 7.0.3
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-04-22 19:55:55 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Andrej Nemec 2017-11-14 03:45:47 EST
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

External References:

https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-017_itext_xml_external_entity_attack.txt
Comment 1 Andrej Nemec 2017-11-14 03:46:11 EST
Created itext tracking bugs for this issue:

Affects: fedora-all [bug 1512828]

Note You need to log in before you can comment on or make changes to this bug.