Candidate: CVE-2018-1000069 PublicDate: 2018-03-13 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000069 https://www.freeplane.org/wiki/index.php/XML_External_Entity_vulnerability_in_map_parser https://www.youtube.com/watch?v=7IXtiTNilAI Description: FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N [5.5 MEDIUM] Patches_freeplane: upstream: https://github.com/freeplane/freeplane/commit/a5dce7f9f upstream_freeplane: released (1.6.6-1) precise/esm_freeplane: DNE trusty_freeplane: ignored (reached end-of-life) trusty/esm_freeplane: DNE (trusty was needs-triage) xenial_freeplane: ignored (end of standard support, was needed) artful_freeplane: ignored (reached end-of-life) bionic_freeplane: not-affected (1.6.6-1) cosmic_freeplane: ignored (reached end-of-life) disco_freeplane: not-affected (1.6.6-1) eoan_freeplane: not-affected (1.6.6-1) focal_freeplane: not-affected (1.6.6-1) groovy_freeplane: not-affected (1.6.6-1) hirsute_freeplane: not-affected (1.6.6-1) impish_freeplane: not-affected (1.6.6-1) jammy_freeplane: not-affected (1.6.6-1) devel_freeplane: not-affected (1.6.6-1)