CVE-2014-2053CVE-2014-2053

Affected configuration(s):

cpe:/a:getid3:getid3:1.9.0
cpe:/a:getid3:getid3:1.9.1
cpe:/a:getid3:getid3:1.9.2
cpe:/a:getid3:getid3:1.9.3
cpe:/a:getid3:getid3:1.9.4:b1
cpe:/a:getid3:getid3:1.9.5
cpe:/a:getid3:getid3:1.9.6
cpe:/a:getid3:getid3:1.9.7
cpe:/a:owncloud:owncloud:5.0.0
cpe:/a:owncloud:owncloud:5.0.1
cpe:/a:owncloud:owncloud:5.0.2
cpe:/a:owncloud:owncloud:5.0.3
cpe:/a:owncloud:owncloud:5.0.4
cpe:/a:owncloud:owncloud:5.0.5
cpe:/a:owncloud:owncloud:5.0.6
cpe:/a:owncloud:owncloud:5.0.7
cpe:/a:owncloud:owncloud:5.0.8
cpe:/a:owncloud:owncloud:5.0.9
cpe:/a:owncloud:owncloud:5.0.10
cpe:/a:owncloud:owncloud:5.0.11
cpe:/a:owncloud:owncloud:5.0.12
cpe:/a:owncloud:owncloud:5.0.13
cpe:/a:owncloud:owncloud:5.0.14
cpe:/a:owncloud:owncloud:5.0.14:a
cpe:/a:owncloud:owncloud:6.0.0
cpe:/a:owncloud:owncloud:6.0.1

Date published: 2014-06-04T10:55:03.840-04:00

Date last modified: 2017-01-06T21:59:45.173-05:00

CVSS Score: 7.5

Principal attack vector: NETWORK

Complexity:  LOW

Reference URL: http://getid3.sourceforge.net/source/changelog.txt

Summary: getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.