Apache product_box XML external entity Injection Vulnerability (CVE-2016-2175)
Apache product_box XML external entity Injection Vulnerability (CVE-2016-2175)
Release date:
Updated on:
Affected Systems:
Apache Group consumer box <1.8.12
Apache Group consumer box 2.x <2.0.1
Apache Group consumer box
Description:
CVE (CAN) ID: CVE-2016-2175
The Apache product_box library is an open-source Java tool for PDF documentation.
Apache javasbox <1.8.12, 2.x <2.0.1 versions do not correctly initialize the XML parser. Attackers with independent context can execute XML external entity attacks by constructing PDF files.
<* Source: Florian Weimer
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://svn.apache.org/viewvc? View = revision & revision = 1739565
Http://svn.apache.org/viewvc? View = revision & revision = 1739564
Parse PDF files using product_box
Use product_box to process PDF documents
Product_box details: click here
Product_box: click here
This article permanently updates the link address: