High severityNVD Advisory· Published Jun 4, 2014· Updated Jun 17, 2026
CVE-2014-2053
CVE-2014-2053
Description
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
james-heinrich/getid3Packagist | < 1.9.9 | 1.9.9 |
Affected products
28<5.0.15 (<5.0.15) or >=6.0.0,<6.0.2+ 18 more
- (no CPE)range: <5.0.15 (<5.0.15) or >=6.0.0,<6.0.2
- cpe:2.3:a:owncloud:owncloud_server:*:a:*:*:*:*:*:*range: <=5.0.14
- cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:getid3:getid3:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:getid3:getid3:*:*:*:*:*:*:*:*range: <=1.9.7
- cpe:2.3:a:getid3:getid3:1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:getid3:getid3:1.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:getid3:getid3:1.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:getid3:getid3:1.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:getid3:getid3:1.9.4:b1:*:*:*:*:*:*
- cpe:2.3:a:getid3:getid3:1.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:getid3:getid3:1.9.6:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- owncloud.org/about/security/advisories/oC-SA-2014-006/nvdVendor Advisory
- github.com/advisories/GHSA-5v43-55m5-qr8fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-2053ghsaADVISORY
- getid3.sourceforge.net/source/changelog.txtnvdWEB
- owncloud.org/about/security/advisories/oC-SA-2014-006ghsaWEB
- secunia.com/advisories/58002nvdWEB
- www.debian.org/security/2014/dsa-3001nvdWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/james-heinrich/getid3/CVE-2014-2053.yamlghsaWEB
- github.com/JamesHeinrich/getID3/commit/afbdaa044a9a0a9dff2f800bd670e231b3ec99b2ghsaWEB
- wordpress.org/news/2014/08/wordpress-3-9-2ghsaWEB
- wordpress.org/news/2014/08/wordpress-3-9-2/nvd
News mentions
0No linked articles in our index yet.