Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-1626

Опубликовано: 26 янв. 2014
Источник: debian

Описание

XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmarc-xml-perlfixed1.0.2-1package
libmarc-xml-perlno-dsawheezypackage
libmarc-xml-perlno-dsasqueezepackage

Примечания

  • http://sourceforge.net/p/marcpm/code/ci/cf2d36597a56eeeffd53b38182b8557c7bf569ac/

  • older versions do not have the ability to set a user custom parser, trying to fix CVE-2014-1626 not clear yet

  • upstream developer contacted and is looking into it; backport fix might be to intrusive due to change in used Module

Связанные уязвимости

ubuntu
около 12 лет назад

XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.

nvd
около 12 лет назад

XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.

github
больше 3 лет назад

XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.