CVE Vulnerabilities

CVE-2013-4701

Published: Aug 21, 2013 | Modified: Nov 28, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected Software

Name Vendor Start Version End Version
Php-openid Janrain * 2.2.2 (including)
Php-openid Ubuntu lucid *
Php-openid Ubuntu precise *
Php-openid Ubuntu quantal *
Php-openid Ubuntu raring *
Php-openid Ubuntu saucy *
Php-openid Ubuntu upstream *
Php-openid Ubuntu utopic *
Php-openid Ubuntu vivid *
Php-openid Ubuntu wily *

References