From 84014f14365da2a15b0ddd4feb25f5867c10033e Mon Sep 17 00:00:00 2001 From: Nathan Owens Date: Wed, 23 Oct 2019 15:14:12 -0500 Subject: [PATCH] textproc/uniconv: add vuxml entry --- security/vuxml/vuln.xml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 4bd89d2ca9ab..73732db76122 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,33 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + SSRF and local file inclusion + + + unoconv + 0.9 + + + + +

mitre

+
+

escription + The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.

+
+ +
+ + https://buer.haus/2019/10/18/a-tale-of-exploitation-in-spreadsheet-file-conversions/ + https://github.com/unoconv/unoconv/pull/510 + + + 2019-10-09 + 2019-10-21 + +
+ Loofah -- XSS vulnerability -- 2.23.0