Raptor contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when processing XML external entities in certain XML components within an RDF document, which will disclose contents of arbitrary files to a context-dependent attacker.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified
Solution
Upgrade to version 2.0.7 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.