CVE-2014-2053

EUVD-2022-2656
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
getid3getid3
𝑥
≤ 1.9.7
getid3getid3
1.9.0
getid3getid3
1.9.1
getid3getid3
1.9.2
getid3getid3
1.9.3
getid3getid3
1.9.4:b1
getid3getid3
1.9.5
getid3getid3
1.9.6
owncloudowncloud_server
𝑥
≤ 5.0.14
owncloudowncloud_server
5.0.0
owncloudowncloud_server
5.0.1
owncloudowncloud_server
5.0.2
owncloudowncloud_server
5.0.3
owncloudowncloud_server
5.0.4
owncloudowncloud_server
5.0.5
owncloudowncloud_server
5.0.6
owncloudowncloud_server
5.0.7
owncloudowncloud_server
5.0.8
owncloudowncloud_server
5.0.9
owncloudowncloud_server
5.0.10
owncloudowncloud_server
5.0.11
owncloudowncloud_server
5.0.12
owncloudowncloud_server
5.0.13
owncloudowncloud_server
5.0.14
getid3getid3
𝑥
≤ 1.9.7
getid3getid3
1.9.0
getid3getid3
1.9.1
getid3getid3
1.9.2
getid3getid3
1.9.3
getid3getid3
1.9.4:b1
getid3getid3
1.9.5
getid3getid3
1.9.6
owncloudowncloud_server
6.0.0
owncloudowncloud_server
6.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-getid3
bookworm
1.9.22+dfsg-1
fixed
bullseye
1.9.20+dfsg-1
fixed
sid
1.9.23+dfsg-1
fixed
squeeze
not-affected
trixie
1.9.23+dfsg-1
fixed
wordpress
bookworm
6.1.6+dfsg1-0+deb12u1
fixed
bookworm (security)
6.1.6+dfsg1-0+deb12u1
fixed
bullseye
5.7.11+dfsg1-0+deb11u1
fixed
bullseye (security)
5.7.11+dfsg1-0+deb11u1
fixed
sid
6.6.1+dfsg1-1
fixed
squeeze
not-affected
trixie
6.6.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
artful
dne
bionic
dne
cosmic
dne
disco
dne
lucid
dne
precise
not-affected
saucy
ignored
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
php-getid3
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
lucid
ignored
precise
ignored
saucy
ignored
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected