Bug 1034677 - (CVE-2017-5661) VUL-1: CVE-2017-5661: fop,xmlgraphics-fop: [CVE-2017-5661] Apache XML Graphics FOP information disclosure vulnerability
(CVE-2017-5661)
VUL-1: CVE-2017-5661: fop,xmlgraphics-fop: [CVE-2017-5661] Apache XML Graphic...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/183755/
CVSSv2:SUSE:CVE-2017-5661:3.6:(AV:L/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-04-18 15:25 UTC by Marcus Meissner
Modified: 2022-09-23 06:58 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-04-18 15:25:27 UTC
CVE-2017-5661

CVE-2017-5661:
        Apache XML Graphics FOP information disclosure vulnerability

Severity:
        Medium

Vendor:
        The Apache Software Foundation

Versions Affected:
        FOP 1.0 - 2.1

Description:
        Files lying on the filesystem of the server which uses batik can
        be revealed to arbitrary users who send maliciously formed SVG
        files. The file types that can be shown depend on the user context
        in which the exploitable application is running. If the user is root
        a full compromise of the server--including confidential or sensitive
        files--would be possible.

        XXE can also be used to attack the availability of the server
        via denial of service as the references within a xml document
        can trivially trigger an amplification attack.

Mitigation:
        Users should upgrade to FOP 2.2+

Credit:
        This issue was independently reported by Pierre Ernst at Salesforce.

References:
        http://xmlgraphics.apache.org/security.html

The Apache XML Graphics team.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5661
http://seclists.org/oss-sec/2017/q2/86
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5661