CVE Vulnerabilities

CVE-2014-2053

Published: Jun 04, 2014 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Affected Software

Name Vendor Start Version End Version
Getid3 Getid3 * 1.9.7 (including)
Getid3 Getid3 1.9.0 (including) 1.9.0 (including)
Getid3 Getid3 1.9.1 (including) 1.9.1 (including)
Getid3 Getid3 1.9.2 (including) 1.9.2 (including)
Getid3 Getid3 1.9.3 (including) 1.9.3 (including)
Getid3 Getid3 1.9.4-b1 (including) 1.9.4-b1 (including)
Getid3 Getid3 1.9.5 (including) 1.9.5 (including)
Getid3 Getid3 1.9.6 (including) 1.9.6 (including)
Owncloud Owncloud * 5.0.14 (including)
Owncloud Owncloud 5.0.0 (including) 5.0.0 (including)
Owncloud Owncloud 5.0.1 (including) 5.0.1 (including)
Owncloud Owncloud 5.0.2 (including) 5.0.2 (including)
Owncloud Owncloud 5.0.3 (including) 5.0.3 (including)
Owncloud Owncloud 5.0.4 (including) 5.0.4 (including)
Owncloud Owncloud 5.0.5 (including) 5.0.5 (including)
Owncloud Owncloud 5.0.6 (including) 5.0.6 (including)
Owncloud Owncloud 5.0.7 (including) 5.0.7 (including)
Owncloud Owncloud 5.0.8 (including) 5.0.8 (including)
Owncloud Owncloud 5.0.9 (including) 5.0.9 (including)
Owncloud Owncloud 5.0.10 (including) 5.0.10 (including)
Owncloud Owncloud 5.0.11 (including) 5.0.11 (including)
Owncloud Owncloud 5.0.12 (including) 5.0.12 (including)
Owncloud Owncloud 5.0.13 (including) 5.0.13 (including)
Owncloud Owncloud 5.0.14 (including) 5.0.14 (including)
Owncloud Ubuntu saucy *
Owncloud Ubuntu upstream *
Php-getid3 Ubuntu lucid *
Php-getid3 Ubuntu precise *
Php-getid3 Ubuntu saucy *
Php-getid3 Ubuntu trusty *
Php-getid3 Ubuntu upstream *

References