LibreOffice < 3.4.6 / 3.5.1 XML External Entity RDF Document Handling Information Disclosure

This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.

Synopsis :

The remote host is running an application affected by a data leakage

Description :

The remote host is running a version of LibreOffice < 3.4.6 / 3.5.1
that has flaws in the way certain XML components are processed for
external entities in ODF documents. These flaws can be utilized to
access and inject the content of local files into an ODF document
without a user's knowledge or permission, or inject arbitrary code
that would be executed when opened by the user.

See also :

Solution :

Upgrade to LibreOffice 3.4.6 / 3.5.1 or higher.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 58726 ()

Bugtraq ID: 52681

CVE ID: CVE-2012-0037

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now