CVE Database
/

CVE-2016-9487

Back to search

CVE-2016-9487

Published: Jul 13, 2018

Modified: Aug 6, 2024

PUBLISHED

Description

EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit this behavior to read arbitrary files, or have the victim execute arbitrary requests on his behalf, abusing the victim's trust relationship with other entities.

VendorProductVersions

EpubCheck

EpubCheck

affected
4.0.1

Weaknesses (CWE)

References

VU#779243
third-party-advisory
x_refsource_CERT-VN
94864
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now