CVE-2016-2175

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
References
Link Resource
http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3E
http://packetstormsecurity.com/files/137214/Apache-PDFBox-1.8.11-2.0.0-XML-Injection.html
http://rhn.redhat.com/errata/RHSA-2017-0179.html
http://rhn.redhat.com/errata/RHSA-2017-0248.html
http://rhn.redhat.com/errata/RHSA-2017-0249.html
http://rhn.redhat.com/errata/RHSA-2017-0272.html
http://svn.apache.org/viewvc?view=revision&revision=1739564 Patch Vendor Advisory
http://svn.apache.org/viewvc?view=revision&revision=1739565 Patch Vendor Advisory
http://www.debian.org/security/2016/dsa-3606 Third Party Advisory
http://www.securityfocus.com/archive/1/538503/100/0/threaded
http://www.securityfocus.com/bid/90902
https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E
http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3E
http://packetstormsecurity.com/files/137214/Apache-PDFBox-1.8.11-2.0.0-XML-Injection.html
http://rhn.redhat.com/errata/RHSA-2017-0179.html
http://rhn.redhat.com/errata/RHSA-2017-0248.html
http://rhn.redhat.com/errata/RHSA-2017-0249.html
http://rhn.redhat.com/errata/RHSA-2017-0272.html
http://svn.apache.org/viewvc?view=revision&revision=1739564 Patch Vendor Advisory
http://svn.apache.org/viewvc?view=revision&revision=1739565 Patch Vendor Advisory
http://www.debian.org/security/2016/dsa-3606 Third Party Advisory
http://www.securityfocus.com/archive/1/538503/100/0/threaded
http://www.securityfocus.com/bid/90902
https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:pdfbox:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.11:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc3:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:47

Type Values Removed Values Added
References () http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3E - () http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3E -
References () http://packetstormsecurity.com/files/137214/Apache-PDFBox-1.8.11-2.0.0-XML-Injection.html - () http://packetstormsecurity.com/files/137214/Apache-PDFBox-1.8.11-2.0.0-XML-Injection.html -
References () http://rhn.redhat.com/errata/RHSA-2017-0179.html - () http://rhn.redhat.com/errata/RHSA-2017-0179.html -
References () http://rhn.redhat.com/errata/RHSA-2017-0248.html - () http://rhn.redhat.com/errata/RHSA-2017-0248.html -
References () http://rhn.redhat.com/errata/RHSA-2017-0249.html - () http://rhn.redhat.com/errata/RHSA-2017-0249.html -
References () http://rhn.redhat.com/errata/RHSA-2017-0272.html - () http://rhn.redhat.com/errata/RHSA-2017-0272.html -
References () http://svn.apache.org/viewvc?view=revision&revision=1739564 - Patch, Vendor Advisory () http://svn.apache.org/viewvc?view=revision&revision=1739564 - Patch, Vendor Advisory
References () http://svn.apache.org/viewvc?view=revision&revision=1739565 - Patch, Vendor Advisory () http://svn.apache.org/viewvc?view=revision&revision=1739565 - Patch, Vendor Advisory
References () http://www.debian.org/security/2016/dsa-3606 - Third Party Advisory () http://www.debian.org/security/2016/dsa-3606 - Third Party Advisory
References () http://www.securityfocus.com/archive/1/538503/100/0/threaded - () http://www.securityfocus.com/archive/1/538503/100/0/threaded -
References () http://www.securityfocus.com/bid/90902 - () http://www.securityfocus.com/bid/90902 -
References () https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E - () https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E -

07 Nov 2023, 02:31

Type Values Removed Values Added
References
  • {'url': 'http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8@apache.org%3E', 'name': '[www-announce] 20160527 [CVE-2016-2175] Apache PDFBox XML External Entity vulnerability', 'tags': ['Mailing List'], 'refsource': 'MLIST'}
  • {'url': 'https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54@%3Ccommits.tika.apache.org%3E', 'name': '[tika-commits] 20190802 svn commit: r1864259 [1/17] - in /tika/site: publish/ publish/1.10/ publish/1.11/ publish/1.12/ publish/1.13/ publish/1.14/ publish/1.15/ publish/1.16/ publish/1.17/ publish/1.18/ publish/1.19.1/ publish/1.19/ publish/1.20/ publish/1.21/ publish/1.22/ ...', 'tags': [], 'refsource': 'MLIST'}
  • () http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3E -
  • () https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E -

Information

Published : 2016-06-01 20:59

Updated : 2024-11-21 02:47


NVD link : CVE-2016-2175

Mitre link : CVE-2016-2175

CVE.ORG link : CVE-2016-2175


JSON object : View

Products Affected

debian

  • debian_linux

apache

  • pdfbox