CVE Vulnerabilities

CVE-2016-2175

Published: Jun 01, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Affected Software

NameVendorStart VersionEnd Version
PdfboxApache1.8.0 (including)1.8.0 (including)
PdfboxApache1.8.1 (including)1.8.1 (including)
PdfboxApache1.8.2 (including)1.8.2 (including)
PdfboxApache1.8.3 (including)1.8.3 (including)
PdfboxApache1.8.4 (including)1.8.4 (including)
PdfboxApache1.8.5 (including)1.8.5 (including)
PdfboxApache1.8.6 (including)1.8.6 (including)
PdfboxApache1.8.7 (including)1.8.7 (including)
PdfboxApache1.8.8 (including)1.8.8 (including)
PdfboxApache1.8.9 (including)1.8.9 (including)
PdfboxApache1.8.10 (including)1.8.10 (including)
PdfboxApache1.8.11 (including)1.8.11 (including)
PdfboxApache2.0 (including)2.0 (including)
PdfboxApache2.0-rc1 (including)2.0-rc1 (including)
PdfboxApache2.0-rc2 (including)2.0-rc2 (including)
PdfboxApache2.0-rc3 (including)2.0-rc3 (including)
Red Hat JBoss A-MQ 6.3RedHat*
Red Hat JBoss BPMS 6.4RedHat*
Red Hat JBoss BRMS 6.4RedHat*
Red Hat JBoss Data Virtualization 6.3RedHatpdfbox*
Red Hat JBoss Fuse 6.3RedHat*
Libpdfbox-javaUbuntuesm-apps/xenial*
Libpdfbox-javaUbuntuprecise*
Libpdfbox-javaUbuntutrusty*
Libpdfbox-javaUbuntuupstream*
Libpdfbox-javaUbuntuwily*
Libpdfbox-javaUbuntuxenial*

References