CVE-2012-0037: Apache Openoffice
Medium severity, CVSS 6.5. EPSS: 13.7% chance of exploitation in the next 30 days.
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
Affected products
- Apache Openoffice: version 3.3.0 only; version 3.4.0 only
- Debian Debian Linux: version 6.0 only
- Fedoraproject Fedora: version 16 only; version 17 only
- Librdf Raptor: before 2.0.7 (fixed in 2.0.7)
- Libreoffice Libreoffice: before 3.4.6 (fixed in 3.4.6); version 3.5.0 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.2 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 6.2 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Red Hat Gluster Storage Server For On-Premise: version 2.0 only
- Red Hat Storage: version 2.0 only
- Red Hat Storage For Public Cloud: version 2.0 only
Published 2012-06-17. Last modified 2026-06-16.