Overview
EpubCheck 4.0.1 is vulnerable to external XML entity processing attacks.
Description
EpubCheck is a tool to validate that EPUB files follow the proper format. It can be used as a stand alone command line utility, or included in a project (most commonly being epub readers) as a library. CWE-611: Improper Restriction of XML External Entity Reference ('XXE') - CVE-2016-9487 |
Impact
A remote attacker may be able to access arbitrary files on a system, or cause the system execute arbitrary requests. |
Solution
Apply an update EpubCheck has released version 4.0.2 to address the vulnerability. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 5.9 | E:--/RL:OF/RC:C |
Environmental | 4.5 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Craig Arendt for reporting this vulnerability.
This document was written by Trent Novelly.
Other Information
CVE IDs: | CVE-2016-9487 |
Date Public: | 2016-12-13 |
Date First Published: | 2016-12-13 |
Date Last Updated: | 2016-12-14 18:20 UTC |
Document Revision: | 15 |