FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1643

This CVE name corresponds to:

Entered Topic
2013-03-18 php5 -- Multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1643
Phase Assigned(20130210)

Description

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.

References

Source Reference
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702221
CONFIRM https://bugs.gentoo.org/show_bug.cgi?id=459904
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=918187
CONFIRM http://git.php.net/?p=php-src.git;a=commit;h=8e76d0404b7f664ee6719fd98f0483f0ac4669d6
CONFIRM http://www.php.net/ChangeLog-5.php
CONFIRM http://support.apple.com/kb/HT5880
CONFIRM https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0101
APPLE APPLE-SA-2013-09-12-1
DEBIAN DSA-2639
MANDRIVA MDVSA-2013:114
REDHAT RHSA-2013:1307
REDHAT RHSA-2013:1615
SUSE SUSE-SU-2013:1285
SUSE SUSE-SU-2013:1315
UBUNTU USN-1761-1
SECUNIA 55078