LWN.net Logo

php-pear-Auth-OpenID: denial of service

Package(s):php-pear-Auth-OpenID CVE #(s):CVE-2013-4701
Created:September 3, 2013 Updated:September 16, 2013
Description: From the CVE entry:

Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Alerts:
Fedora FEDORA-2013-15258 2013-09-01
Fedora FEDORA-2013-15253 2013-09-01
Mageia MGASA-2013-0272 2013-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds