Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4175-1
Wojciech Regu?a discovered that Freeplane, a program for working with mind maps, was affected by a XML External Entity (XXE) vulnerability in its mindmap loader that could compromise a user's machine by opening a specially crafted mind map file. . Package : freeplane Version : 1.1.3-2+deb7u1 CVE ID : CVE-2018-1000069 Debian Bug : 893663 Wojciech Regu?a discovered that Freeplane, a program for working with mind maps, was affected by a XML External Entity (XXE) vulnerability in its mindmap loader that could compromise a user's machine by opening a specially crafted mind map file. For Debian 7 "Wheezy", these problems have been fixed in version 1.1.3-2+deb7u1. We recommend that you upgrade your freeplane packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest Freeplane patch tackles a critical XXE vulnerability, safeguarding against malicious mind map documents on Debian systems. Users are urged to upgrade!. Freeplane Security Update, XML External Entity Debian, Debian 7 Freeplane Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.