CVE Vulnerabilities

CVE-2016-4216

Published: Jul 13, 2016 | Modified: Nov 28, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected Software

Name Vendor Start Version End Version
Xmp_toolkit Adobe * 5.1.2 (including)
Libxmpcore-java Ubuntu artful *
Libxmpcore-java Ubuntu bionic *
Libxmpcore-java Ubuntu cosmic *
Libxmpcore-java Ubuntu devel *
Libxmpcore-java Ubuntu disco *
Libxmpcore-java Ubuntu eoan *
Libxmpcore-java Ubuntu esm-apps/bionic *
Libxmpcore-java Ubuntu esm-apps/xenial *
Libxmpcore-java Ubuntu focal *
Libxmpcore-java Ubuntu groovy *
Libxmpcore-java Ubuntu hirsute *
Libxmpcore-java Ubuntu impish *
Libxmpcore-java Ubuntu jammy *
Libxmpcore-java Ubuntu kinetic *
Libxmpcore-java Ubuntu lunar *
Libxmpcore-java Ubuntu mantic *
Libxmpcore-java Ubuntu noble *
Libxmpcore-java Ubuntu oracular *
Libxmpcore-java Ubuntu trusty *
Libxmpcore-java Ubuntu upstream *
Libxmpcore-java Ubuntu wily *
Libxmpcore-java Ubuntu xenial *
Libxmpcore-java Ubuntu yakkety *
Libxmpcore-java Ubuntu zesty *

References