VDB

GCVE-110-MAGEIA-2013-272

GCVE-110-MAGEIA-2013-272
Advisory Published
Vulnetix · Advisory published September 13, 2013
Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue (CVE-2013-4701).

Affected Products

VendorProductVersionsPlatforms
Mageiaphp-pear-Auth_OpenID0 (affected), 2.2.2-1.mga2 (unaffected)
Mageiaphp-pear-Auth_OpenID0 (affected), 2.2.2-1.mga3 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›