Описание
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| owncloud | fixed | 6.0.2+dfsg-1 | package | |
| dolibarr | fixed | 3.5.3+dfsg1-1 | package | |
| moodle | fixed | 2.7.5+dfsg-3 | package | |
| moodle | end-of-life | squeeze | package |
Примечания
dolibarr removed phpexcel in 3.5.3+dfsg1-1 / #729538
moodle also contain a copy of PHPExcel
owncloud does not mention details
http://owncloud.org/about/security/advisories/oC-SA-2014-006/
https://github.com/PHPOffice/PHPExcel/blob/develop/changelog.txt
EPSS
Связанные уязвимости
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
EPSS