CVE-2016-2175

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:pdfbox:2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.11:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:1.8.8:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Information

Published : 2016-06-01 13:59

Updated : 2018-10-09 12:59


NVD link : CVE-2016-2175

Mitre link : CVE-2016-2175


JSON object : View

Advertisement

dedicated server usa

Products Affected

debian

  • debian_linux

apache

  • pdfbox