Debian Security Advisory

DLA-1299-1 libjgraphx-java -- LTS security update

Date Reported:
04 Mar 2018
Affected Packages:
libjgraphx-java
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-18197.
More information:

It was discovered that there was a potential XML External Entity (XXE) attack in libjgraphx-java, a diagramming library for Java applications.

For Debian 7 Wheezy, this issue has been fixed in libjgraphx-java version 1.4.1.0-3+deb7u1.

We recommend that you upgrade your libjgraphx-java packages.