CVE-2016-3674
Summary
| CVE | CVE-2016-3674 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-05-17 14:08:00 UTC |
| Updated | 2018-03-26 18:47:00 UTC |
| Description | Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - CVE request - XStream: XXE vulnerability |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Broken Link |
| IBM Lotus Domino XML External Entity Processing Flaw in XStream Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 22 Update: xstream-1.4.9-1.fc22 |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| XStream CVE-2016-3674 XML External Entity Multiple Information Disclosure Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| oss-security - Re: CVE request - XStream: XXE vulnerability |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| XXE vulnerability · Issue #25 · x-stream/xstream · GitHub |
CONFIRM |
github.com |
Vendor Advisory |
| [SECURITY] Fedora 23 Update: xstream-1.4.9-1.fc23 |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Broken Link |
| Debian -- Security Information -- DSA-3575-1 libxstream-java |
DEBIAN |
www.debian.org |
Third Party Advisory |
| XStream - Change History |
CONFIRM |
x-stream.github.io |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375827 XStream Arbitrary Code Execution And Multiple vulnerabilities
- 730155 McAfee Web Gateway Multiple Vulnerabilities(WP-3580, WP-3656, WP-3815, WP-3878, WP-3882, WP-3934,WP-3935, WP-3936, WP-3999)
- 980759 Java (maven) Security Update for com.thoughtworks.xstream:xstream (GHSA-rgh3-987h-wpmw)