CVE-2014-2053: XEE
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Other sources
getID3() before 1.9.9, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2053?
CVE-2014-2053 is classified as a medium severity vulnerability that can lead to remote file reading and denial of service.
How do I fix CVE-2014-2053?
To mitigate CVE-2014-2053, upgrade to getID3 version 1.9.9 or higher.
Which versions of ownCloud are affected by CVE-2014-2053?
CVE-2014-2053 affects ownCloud versions prior to 5.0.15 and 6.0.x before 6.0.2.
What types of attacks can CVE-2014-2053 enable?
CVE-2014-2053 can enable XML External Entity (XXE) attacks, leading to file disclosure and denial of service.
Is there a workaround for CVE-2014-2053?
There are no known workarounds for CVE-2014-2053; the recommended action is to update to the latest version.