Bug 1572380 (CVE-2017-8315) - CVE-2017-8315 eclipse-andmore: XML External Entity attack in AndroidManifest.xml parsing
Summary: CVE-2017-8315 eclipse-andmore: XML External Entity attack in AndroidManifest....
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2017-8315
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1572381 1572382
Blocks: 1572383
TreeView+ depends on / blocked
 
Reported: 2018-04-26 22:04 UTC by Laura Pardo
Modified: 2019-09-29 14:37 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-05-16 21:29:44 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Eclipse Project 519169 0 None None None 2018-04-27 09:02:51 UTC

Description Laura Pardo 2018-04-26 22:04:05 UTC
Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.


References:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169
https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/

Comment 1 Laura Pardo 2018-04-26 22:04:36 UTC
Created eclipse tracking bugs for this issue:

Affects: fedora-all [bug 1572381]

Comment 3 Mat Booth 2018-04-27 09:07:57 UTC
The upstream bug you cite shows that the Android tooling component called "Andmore" is affected and we do not ship that component in any Fedora or RHEL product.

Can you show that vulnerability exists in any component that we do ship? If not I would like to close this as NOTABUG.

Comment 4 Tomas Hoger 2018-05-03 21:12:11 UTC
I can not find any actionable public information about the flaw, and the upstream bug is restricted.  The original report from Checkpoint does not provide any details on how and where Eclipse is affected.

As you have access to the upstream bug, can you point out upstream fix for this, if it was fixed already?  Checkpoint report indicates issues were reported to relevant upstreams about a year ago.  However, I could not find anything obviously related in the Andmore git repo, and there's very little activity there at all.  So wonder if this remains unfixed upstream.

Comment 5 Alexander Kurtakov 2018-05-03 21:27:33 UTC
The upstream bug is against andmore/core so definetely not smth we should care about as we do not ship it.

Comment 7 Tomas Hoger 2018-05-03 21:45:28 UTC
What is the status of the upstream bug?  Is it open with no fix committed or proposed?

Comment 8 Alexander Kurtakov 2018-05-03 21:49:39 UTC
Open with no fix committed or proposed - yes.

Comment 11 Tomas Hoger 2018-05-16 21:29:44 UTC
This affects Eclipse Andmore project, which is not included in Eclipse packages included in Red Hat products.


Note You need to log in before you can comment on or make changes to this bug.