Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2175

Опубликовано: 27 мая 2016
Источник: redhat
CVSS3: 5.4
CVSS2: 5.8

Описание

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6pdfboxAffected
Red Hat JBoss BRMS 6pdfboxAffected
Red Hat JBoss Fuse 6pdfboxAffected
Red Hat JBoss Fuse Service Works 6pdfboxNot affected
Red Hat JBoss Portal 6pdfboxWill not fix
Red Hat Satellite 5pdfboxAffected
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:017919.01.2017
Red Hat JBoss BPMS 6.4FixedRHSA-2017:024902.02.2017
Red Hat JBoss BRMS 6.4FixedRHSA-2017:024802.02.2017
Red Hat JBoss Data Virtualization 6.3pdfboxFixedRHSA-2017:027214.02.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1340396pdfbox: XML External Entity vulnerability

5.4 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

CVSS3: 7.8
nvd
больше 9 лет назад

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

CVSS3: 7.8
debian
больше 9 лет назад

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly ini ...

CVSS3: 7.8
github
больше 7 лет назад

High severity vulnerability that affects org.apache.pdfbox:pdfbox

5.4 Medium

CVSS3

5.8 Medium

CVSS2