Bug#1144952: rdf4j: CVE-2018-1000644

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178725098474.4001212.2954557289539562486.reportbug__23457.7973418467$1787251039$gmane$org@eldamar.lan>
Source: rdf4j
Version: 3.7.7+ds-1
Severity: grave
Tags: security upstream
Forwarded: https://github.com/eclipse-rdf4j/rdf4j/issues/1056
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for rdf4j.

CVE-2018-1000644[0]:
| Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External
| Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files
| that can result in the disclosure of confidential data, denial of
| service, server side request forgery, port scanning. This attack
| appear to be exploitable via Specially crafted RDF file.

Please note that the issue recently got a second CVE assigned,
CVE-2026-15803 for an incomplete fix of the original CVE-2018-1000644.
So once fixing this issue, make sure to fix it completely following
[3].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-1000644
    https://www.cve.org/CVERecord?id=CVE-2018-1000644
[1] https://github.com/eclipse-rdf4j/rdf4j/issues/1056
[2] https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135
[3] https://gitlab.eclipse.org/security/cve-assignment/-/work_items/175

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.