Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-openid | Janrain | * | 2.2.2 (including) |
Php-openid | Ubuntu | lucid | * |
Php-openid | Ubuntu | precise | * |
Php-openid | Ubuntu | quantal | * |
Php-openid | Ubuntu | raring | * |
Php-openid | Ubuntu | saucy | * |
Php-openid | Ubuntu | upstream | * |
Php-openid | Ubuntu | utopic | * |
Php-openid | Ubuntu | vivid | * |
Php-openid | Ubuntu | wily | * |