LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.
References
Link | Resource |
---|---|
https://0dd.zone/2018/08/05/LatexDraw-XXE/ | Exploit Third Party Advisory |
https://github.com/arnobl/latexdraw/issues/10 | Exploit Issue Tracking Patch Third Party Advisory |
https://0dd.zone/2018/08/05/LatexDraw-XXE/ | Exploit Third Party Advisory |
https://github.com/arnobl/latexdraw/issues/10 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-08-20 19:31
Updated : 2024-11-21 03:40
NVD link : CVE-2018-1000639
Mitre link : CVE-2018-1000639
CVE.ORG link : CVE-2018-1000639
JSON object : View
Products Affected
latexdraw_project
- latexdraw
CWE
CWE-611
Improper Restriction of XML External Entity Reference