10
CVSSv3

CVE-2018-1000825

Published: 20/12/2018 Updated: 08/01/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freecol freecol

Vendor Advisories

Debian Bug report logs - #917023 CVE-2018-1000825 Package: freecol; Maintainer for freecol is Debian Games Team &lt;pkg-games-devel@listsaliothdebianorg&gt;; Source for freecol is src:freecol (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Fri, 21 Dec 2018 15:48:02 UTC Severity: normal Tags ...