MGASA-2013-0272
Dashboard / Vulnerabilities / MGASA-2013-0272
Summary: Updated php-pear-Auth_OpenID package fixes security vulnerability
Details: Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue (CVE-2013-4701).
References: https://advisories.mageia.org/MGASA-2013-0272.html, https://bugs.mageia.org/show_bug.cgi?id=11147, https://lists.fedoraproject.org/pipermail/package-announce/2013-September/115039.html
Affected packages
Package
Name: php-pear-Auth_OpenID
Purl: pkg:rpm/mageia/php-pear-Auth_OpenID?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
