CVE Vulnerabilities

CVE-2016-2175

Published: Jun 01, 2016 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Affected Software

Name Vendor Start Version End Version
Pdfbox Apache 1.8.0 (including) 1.8.0 (including)
Pdfbox Apache 1.8.1 (including) 1.8.1 (including)
Pdfbox Apache 1.8.2 (including) 1.8.2 (including)
Pdfbox Apache 1.8.3 (including) 1.8.3 (including)
Pdfbox Apache 1.8.4 (including) 1.8.4 (including)
Pdfbox Apache 1.8.5 (including) 1.8.5 (including)
Pdfbox Apache 1.8.6 (including) 1.8.6 (including)
Pdfbox Apache 1.8.7 (including) 1.8.7 (including)
Pdfbox Apache 1.8.8 (including) 1.8.8 (including)
Pdfbox Apache 1.8.9 (including) 1.8.9 (including)
Pdfbox Apache 1.8.10 (including) 1.8.10 (including)
Pdfbox Apache 1.8.11 (including) 1.8.11 (including)
Pdfbox Apache 2.0 (including) 2.0 (including)
Pdfbox Apache 2.0-rc1 (including) 2.0-rc1 (including)
Pdfbox Apache 2.0-rc2 (including) 2.0-rc2 (including)
Pdfbox Apache 2.0-rc3 (including) 2.0-rc3 (including)
Red Hat JBoss A-MQ 6.3 RedHat *
Red Hat JBoss BPMS 6.4 RedHat *
Red Hat JBoss BRMS 6.4 RedHat *
Red Hat JBoss Data Virtualization 6.3 RedHat pdfbox *
Red Hat JBoss Fuse 6.3 RedHat *
Libpdfbox-java Ubuntu esm-apps/xenial *
Libpdfbox-java Ubuntu precise *
Libpdfbox-java Ubuntu trusty *
Libpdfbox-java Ubuntu upstream *
Libpdfbox-java Ubuntu wily *
Libpdfbox-java Ubuntu xenial *

References