Candidate: CVE-2017-5992 PublicDate: 2017-02-15 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5992 http://www.openwall.com/lists/oss-security/2017/02/07/5 https://bitbucket.org/openpyxl/openpyxl/issues/749 https://bitbucket.org/openpyxl/openpyxl/commits/3b4905f428e1 Description: Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document. Ubuntu-Description: It was discovered that openpyxl incorrectly handled certain documents. A remote attacker could possibly use this issue to cause a denial of service or other unspecified impact. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854442 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H [8.2 HIGH] Patches_openpyxl: upstream_openpyxl: released (2.3.0-3) precise_openpyxl: ignored (reached end-of-life) precise/esm_openpyxl: DNE (precise was needs-triage) trusty_openpyxl: not-affected (code not present) trusty/esm_openpyxl: not-affected (code not present) vivid/stable-phone-overlay_openpyxl: DNE vivid/ubuntu-core_openpyxl: DNE xenial_openpyxl: ignored (end of standard support, was needed) yakkety_openpyxl: ignored (reached end-of-life) zesty_openpyxl: ignored (reached end-of-life) artful_openpyxl: ignored (reached end-of-life) bionic_openpyxl: not-affected (2.4.9-1) cosmic_openpyxl: not-affected (2.4.9-1) disco_openpyxl: not-affected (2.4.9-1) eoan_openpyxl: not-affected (2.4.9-1) focal_openpyxl: not-affected (2.4.9-1) groovy_openpyxl: not-affected (2.4.9-1) hirsute_openpyxl: not-affected (2.4.9-1) impish_openpyxl: not-affected (2.4.9-1) jammy_openpyxl: not-affected (2.4.9-1) devel_openpyxl: not-affected (2.4.9-1)