CVE-2016-10187: Medium severity calibre vulnerability
Published Mar 16, 2017
·Updated
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
Affected Software
1 affected component
Calibre-ebook Calibre<=2.74.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 16, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10187?
CVE-2016-10187 has a medium severity rating as it allows remote attackers to read arbitrary files.
2
How do I fix CVE-2016-10187?
To fix CVE-2016-10187, upgrade calibre to version 2.75 or later.
3
What types of files can be accessed through CVE-2016-10187?
CVE-2016-10187 allows access to arbitrary files on the system if exploited through a crafted epub file.
4
Which versions of calibre are affected by CVE-2016-10187?
CVE-2016-10187 affects all calibre versions up to 2.74.0.
5
What attack vector is used in CVE-2016-10187?
CVE-2016-10187 is exploited through a crafted epub file that contains JavaScript.