CVE-2016-2175
pdfbox: XML External Entity vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
Apache PDFBox en versiones anteriores a 1.8.12 y 2.x en versiones anteriores a 2.0.1 no inicializa correctamente los analizadores XML, lo que permite a atacantes dependientes del contexto llevar a cabo ataques XML External Entity (XXE) a través de un PDF manipulado.
It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-29 CVE Reserved
- 2016-05-27 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (14)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://svn.apache.org/viewvc?view=revision&revision=1739564 | 2023-11-07 | |
http://svn.apache.org/viewvc?view=revision&revision=1739565 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2017-0179.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0248.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0249.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0272.html | 2023-11-07 | |
http://www.debian.org/security/2016/dsa-3606 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-2175 | 2017-02-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1340396 | 2017-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.0 Search vendor "Apache" for product "Pdfbox" and version "1.8.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.1 Search vendor "Apache" for product "Pdfbox" and version "1.8.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.2 Search vendor "Apache" for product "Pdfbox" and version "1.8.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.3 Search vendor "Apache" for product "Pdfbox" and version "1.8.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.4 Search vendor "Apache" for product "Pdfbox" and version "1.8.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.5 Search vendor "Apache" for product "Pdfbox" and version "1.8.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.6 Search vendor "Apache" for product "Pdfbox" and version "1.8.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.7 Search vendor "Apache" for product "Pdfbox" and version "1.8.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.8 Search vendor "Apache" for product "Pdfbox" and version "1.8.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.9 Search vendor "Apache" for product "Pdfbox" and version "1.8.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.10 Search vendor "Apache" for product "Pdfbox" and version "1.8.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 1.8.11 Search vendor "Apache" for product "Pdfbox" and version "1.8.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0 Search vendor "Apache" for product "Pdfbox" and version "2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0 Search vendor "Apache" for product "Pdfbox" and version "2.0" | rc1 |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0 Search vendor "Apache" for product "Pdfbox" and version "2.0" | rc2 |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0 Search vendor "Apache" for product "Pdfbox" and version "2.0" | rc3 |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|