CVE-2016-2175: High severity apache pdfbox vulnerability
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
Other sources
Apache PDFBox could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.
— IBM
Apache PDFBox parses different XML data within PDF files such as XMP and the initialization of the XML parsers did not protect against XML External Entity (XXE) vulnerabilities.
References:
http://seclists.org/oss-sec/2016/q2/419
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-2175?
CVE-2016-2175 is a vulnerability in Apache PDFBox before 1.8.12 and 2.x before 2.0.1 that allows a remote attacker to obtain sensitive information or cause a denial of service.
How does CVE-2016-2175 affect Apache PDFBox?
CVE-2016-2175 affects Apache PDFBox versions before 1.8.12 and 2.x before 2.0.1, allowing a remote attacker to read arbitrary files on the system or cause a denial of service.
What is the severity of CVE-2016-2175?
CVE-2016-2175 has a severity rating of 7.8 (High).
How can I fix CVE-2016-2175?
To fix CVE-2016-2175, update Apache PDFBox to version 1.8.12 or 2.0.1.
Where can I find more information about CVE-2016-2175?
More information about CVE-2016-2175 can be found at the following references: [http://seclists.org/oss-sec/2016/q2/419](http://seclists.org/oss-sec/2016/q2/419), [https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1340397](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1340397), [https://rhn.redhat.com/errata/RHSA-2017-0179.html](https://rhn.redhat.com/errata/RHSA-2017-0179.html)