Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v43-55m5-qr8f

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

getID3 is vulnerable to XML External Entity (XXE)

getID3() before 1.9.9, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Пакеты

Наименование

james-heinrich/getid3

composer
Затронутые версииВерсия исправления

< 1.9.9

1.9.9

EPSS

Процентиль: 85%
0.02653
Низкий

Дефекты

CWE-611

Связанные уязвимости

ubuntu
больше 11 лет назад

getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

nvd
больше 11 лет назад

getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

debian
больше 11 лет назад

getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6. ...

EPSS

Процентиль: 85%
0.02653
Низкий

Дефекты

CWE-611