CVE-2012-0037

medium
Published 2012-06-17 · Modified 2026-04-29
CVSS v3
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v2
4.3
VIR risk
6.5

Description

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://lists.apache.org/thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.apache.org%3E

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openoffice.org/security/cves/CVE-2012-0037.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.libreoffice.org/advisories/CVE-2012-0037/

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48542

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48529

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48526

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48493

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48479

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://librdf.org/raptor/RELEASE.html#rel2_0_7

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/

OS impact

OSVersionStatusFixed in
redhat rhel5.0affected
redhat rhel6.0affected
redhat rhel6.2affected
fedora fedora16affected
fedora fedora17affected
debian debian6.0affected

Application impact

VendorProductVersionsFixed
librdfraptor{"endExcluding":"2.0.7"}2.0.7
libreofficelibreoffice{"endExcluding":"3.4.6"}3.4.6
libreofficelibreoffice3.5.0
apache apacheopenoffice3.3.0
apache apacheopenoffice3.4.0
redhat redhatgluster_storage_server_for_on-premise2.0
redhat redhatstorage2.0
redhat redhatstorage_for_public_cloud2.0

References

CWEs

CWE-611

Verify integrity in audit chain (admin only). AS-IS.