CVE-2016-2175

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:pdfbox:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.11:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc3:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:31

Type Values Removed Values Added
References
  • {'url': 'http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8@apache.org%3E', 'name': '[www-announce] 20160527 [CVE-2016-2175] Apache PDFBox XML External Entity vulnerability', 'tags': ['Mailing List'], 'refsource': 'MLIST'}
  • {'url': 'https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54@%3Ccommits.tika.apache.org%3E', 'name': '[tika-commits] 20190802 svn commit: r1864259 [1/17] - in /tika/site: publish/ publish/1.10/ publish/1.11/ publish/1.12/ publish/1.13/ publish/1.14/ publish/1.15/ publish/1.16/ publish/1.17/ publish/1.18/ publish/1.19.1/ publish/1.19/ publish/1.20/ publish/1.21/ publish/1.22/ ...', 'tags': [], 'refsource': 'MLIST'}
  • () http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3E -
  • () https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E -

Information

Published : 2016-06-01 20:59

Updated : 2024-02-28 15:21


NVD link : CVE-2016-2175

Mitre link : CVE-2016-2175

CVE.ORG link : CVE-2016-2175


JSON object : View

Products Affected

apache

  • pdfbox

debian

  • debian_linux