CVE-2016-2175
published 2016-06-01CVE-2016-2175: Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External…
PriorityP345high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
4.76%
90.9th percentile
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | tika | — | — |
| apache | tika | — | — |
| apache | tika | >= 0 < 1.18-1 | 1.18-1 |
| debian | debian_linux | — | — |
| debian | libpdfbox-java | < libpdfbox-java 1:1.8.12-1 (bookworm) | libpdfbox-java 1:1.8.12-1 (bookworm) |
| debian | tika | < tika 1.18-1 (bullseye) | tika 1.18-1 (bullseye) |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa7.8HIGH
osv7.8HIGH
vendor_apache7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pdfbox: XML External Entity vulnerability
vendor_redhat·2016-05-27·CVSS 7.8
CVE-2016-2175 [HIGH] CWE-611 pdfbox: XML External Entity vulnerability
pdfbox: XML External Entity vulnerability
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: pdfbox (Red Hat BPM Suite 6) - Affected
Package: pdfbox (Red Hat JBoss BRMS 6) - Affected
Package: pdfbox (Red Hat JBoss Fuse 6) - Affected
Package: pdfbox (Red Hat JBoss Fuse Service Works 6) - Not affected
Package: pdfbox (Red Hat JBoss Portal
Red Hat
tika: XML External Entity vulnerability
vendor_redhat·2016-05-26·CVSS 7.8
CVE-2016-4434 [HIGH] CWE-611 tika: XML External Entity vulnerability
tika: XML External Entity vulnerability
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
It was found that the parsing of OOXML, XMP in PDF, and some other file formats by Apache Tika would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: tika-core (Red Hat BPM Suite 6) - Affected
Package: tika-core (Red Hat JBoss BRMS 5) - Will not fix
Package: tika-core (Red Hat JB
Debian
CVE-2016-4434: tika - Apache Tika before 1.13 does not properly initialize the XML parser or choose ha...
vendor_debian·2016·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434: tika - Apache Tika before 1.13 does not properly initialize the XML parser or choose ha...
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
Scope: local
bullseye: resolved (fixed in 1.18-1)
sid: resolved (fixed in 1.18-1)
Debian
CVE-2016-2175: libpdfbox-java - Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize th...
vendor_debian·2016·CVSS 7.8
CVE-2016-2175 [HIGH] CVE-2016-2175: libpdfbox-java - Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize th...
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
Scope: local
bookworm: resolved (fixed in 1:1.8.12-1)
bullseye: resolved (fixed in 1:1.8.12-1)
forky: resolved (fixed in 1:1.8.12-1)
sid: resolved (fixed in 1:1.8.12-1)
trixie: resolved (fixed in 1:1.8.12-1)
Apache
Apache tika: CVE-2016-2175
vendor_apache·CVSS 7.8
CVE-2016-2175 [HIGH] Apache tika: CVE-2016-2175
Apache tika: CVE-2016-2175
XML External Entity (XXE) in PDFBox ??? ?-1.12
OSV
Apache Tika does not properly initialize the XML parser or choose handlers
osv·2018-10-17·CVSS 7.8
CVE-2016-4434 [HIGH] Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
GHSA
High severity vulnerability that affects org.apache.pdfbox:pdfbox
ghsa·2018-10-17
CVE-2016-2175 [HIGH] CWE-611 High severity vulnerability that affects org.apache.pdfbox:pdfbox
High severity vulnerability that affects org.apache.pdfbox:pdfbox
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
OSV
High severity vulnerability that affects org.apache.pdfbox:pdfbox
osv·2018-10-17
CVE-2016-2175 [HIGH] High severity vulnerability that affects org.apache.pdfbox:pdfbox
High severity vulnerability that affects org.apache.pdfbox:pdfbox
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
GHSA
Apache Tika does not properly initialize the XML parser or choose handlers
ghsa·2018-10-17·CVSS 7.8
CVE-2016-4434 [HIGH] CWE-611 Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
OSV
CVE-2016-4434: Apache Tika before 1
osv·2017-09-30·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434: Apache Tika before 1
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
OSV
CVE-2016-2175: Apache PDFBox before 1
osv·2016-06-01·CVSS 7.8
CVE-2016-2175 [HIGH] CVE-2016-2175: Apache PDFBox before 1
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2175 pdfbox: XML External Entity vulnerability
bugzilla·2016-05-27·CVSS 7.8
CVE-2016-2175 [HIGH] CVE-2016-2175 pdfbox: XML External Entity vulnerability
CVE-2016-2175 pdfbox: XML External Entity vulnerability
Apache PDFBox parses different XML data within PDF files such as XMP and the initialization of the XML parsers did not protect against XML External Entity (XXE) vulnerabilities.
References:
http://seclists.org/oss-sec/2016/q2/419
Discussion:
Created pdfbox tracking bugs for this issue:
Affects: fedora-all [bug 1340397]
---
pdfbox-1.8.8-6.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
---
pdfbox-1.8.11-2.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse/A-MQ 6.3 Rollup 1
Via RHSA-2017:0179
Bugzilla
CVE-2016-2175 pdfbox: XML External Entity vulnerability [fedora-all]
bugzilla·2016-05-27·CVSS 7.8
CVE-2016-2175 [HIGH] CVE-2016-2175 pdfbox: XML External Entity vulnerability [fedora-all]
CVE-2016-2175 pdfbox: XML External Entity vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
http://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3Ehttp://packetstormsecurity.com/files/137214/Apache-PDFBox-1.8.11-2.0.0-XML-Injection.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0179.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0249.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0272.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1739564http://svn.apache.org/viewvc?view=revision&revision=1739565http://www.debian.org/security/2016/dsa-3606http://www.securityfocus.com/archive/1/538503/100/0/threadedhttp://www.securityfocus.com/bid/90902https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3Ehttp://mail-archives.us.apache.org/mod_mbox/www-announce/201605.mbox/%3C83a03bcf-f86b-4688-37b5-615c080291d8%40apache.org%3Ehttp://packetstormsecurity.com/files/137214/Apache-PDFBox-1.8.11-2.0.0-XML-Injection.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0179.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0249.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0272.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1739564http://svn.apache.org/viewvc?view=revision&revision=1739565http://www.debian.org/security/2016/dsa-3606http://www.securityfocus.com/archive/1/538503/100/0/threadedhttp://www.securityfocus.com/bid/90902https://lists.apache.org/thread.html/ad5fbc86c1d1821ae1b963e8561ab6d6a5f66b2848e84f5a31477f54%40%3Ccommits.tika.apache.org%3E
2016-06-01
Published