CVE-2017-5661

Priority
Medium
Description
In Apache FOP before 2.2, files lying on the filesystem of the server which
uses FOP can be revealed to arbitrary users who send maliciously formed SVG
files. The file types that can be shown depend on the user context in which
the exploitable application is running. If the user is root a full
compromise of the server - including confidential or sensitive files -
would be possible. XXE can also be used to attack the availability of the
server via denial of service as the references within a xml document can
trivially trigger an amplification attack.
References
Bugs
Package
Source: fop (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 17.10 (Artful Aardvark):needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:1.1.dfsg-2ubuntu1.1)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 17.04 (Zesty Zapus):needed
Patches:
Upstream:http://svn.apache.org/r1769967
Upstream:http://svn.apache.org/r1769968
More Information

Updated: 2017-08-11 23:25:51 UTC (commit 13081)