Vulnerability Description
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
CVSS Score
5.5
MEDIUM
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Calibre-Ebook | Calibre | <= 2.74.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2017/01/29/8Mailing ListPatch
- http://www.openwall.com/lists/oss-security/2017/01/31/9Mailing ListPatch
- http://www.securityfocus.com/bid/95909Third Party Advisory
- https://bugs.launchpad.net/calibre/+bug/1651728ExploitIssue Tracking
- https://github.com/kovidgoyal/calibre/commit/3a89718664cb8cPatch
- http://www.openwall.com/lists/oss-security/2017/01/29/8Mailing ListPatch
- http://www.openwall.com/lists/oss-security/2017/01/31/9Mailing ListPatch
- http://www.securityfocus.com/bid/95909Third Party Advisory
- https://bugs.launchpad.net/calibre/+bug/1651728ExploitIssue Tracking
- https://github.com/kovidgoyal/calibre/commit/3a89718664cb8cPatch
FAQ
What is CVE-2016-10187?
CVE-2016-10187 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
How severe is CVE-2016-10187?
CVE-2016-10187 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10187?
Check the references section above for vendor advisories and patch information. Affected products include: Calibre-Ebook Calibre.