CVE-2016-2175
01.06.2016, 20:59
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apache | pdfbox | 1.8.0 |
| apache | pdfbox | 1.8.1 |
| apache | pdfbox | 1.8.2 |
| apache | pdfbox | 1.8.3 |
| apache | pdfbox | 1.8.4 |
| apache | pdfbox | 1.8.5 |
| apache | pdfbox | 1.8.6 |
| apache | pdfbox | 1.8.7 |
| apache | pdfbox | 1.8.8 |
| apache | pdfbox | 1.8.9 |
| apache | pdfbox | 1.8.10 |
| apache | pdfbox | 1.8.11 |
| apache | pdfbox | 2.0 |
| apache | pdfbox | 2.0:rc1 |
| apache | pdfbox | 2.0:rc2 |
| apache | pdfbox | 2.0:rc3 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpdfbox-java |
|
References