CVE Vulnerabilities

CVE-2016-2175

Published: Jun 01, 2016 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Affected Software

Name Vendor Start Version End Version
Pdfbox Apache 1.8.0 (including) 1.8.0 (including)
Pdfbox Apache 1.8.1 (including) 1.8.1 (including)
Pdfbox Apache 1.8.2 (including) 1.8.2 (including)
Pdfbox Apache 1.8.3 (including) 1.8.3 (including)
Pdfbox Apache 1.8.4 (including) 1.8.4 (including)
Pdfbox Apache 1.8.5 (including) 1.8.5 (including)
Pdfbox Apache 1.8.6 (including) 1.8.6 (including)
Pdfbox Apache 1.8.7 (including) 1.8.7 (including)
Pdfbox Apache 1.8.8 (including) 1.8.8 (including)
Pdfbox Apache 1.8.9 (including) 1.8.9 (including)
Pdfbox Apache 1.8.10 (including) 1.8.10 (including)
Pdfbox Apache 1.8.11 (including) 1.8.11 (including)
Pdfbox Apache 2.0 (including) 2.0 (including)
Pdfbox Apache 2.0-rc1 (including) 2.0-rc1 (including)
Pdfbox Apache 2.0-rc2 (including) 2.0-rc2 (including)
Pdfbox Apache 2.0-rc3 (including) 2.0-rc3 (including)

References