oss-sec mailing list archives
Re: RE: Handling CVEs for the XML entity expansion issues
From: Tim Brown <tmb () 65535 com>
Date: Thu, 21 Feb 2013 13:54:19 +0000
On Thursday 21 Feb 2013 00:25:19 Kurt Seifried wrote:
On 02/20/2013 06:02 AM, Christey, Steven M. wrote:Kurt, I'm reviewing this issue with the rest of the cve-assign team. We will get back to you with an answer shortly. - SteveAny movement on this? I'm now sitting on a huge pile of stuff that will need CVEs.
To declare, I put forwards a candiate on another language platform to Kurt and Steve which would be affected by a decision to assign CVEs for XXE capable libraries. In this instance, the library has no way to disable XXE at the API level. Below the surface it can use various XML parsers, both native and pure $language. These do not appear to support disabling resolving entities either (although the middleware between the two does :/). I'm am pinging the security team responsible and directing them to this thread. Tim -- Tim Brown <mailto:tmb () 65535 com>
Attachment:
signature.asc
Description: This is a digitally signed message part.
Current thread:
- Handling CVEs for the XML entity expansion issues Kurt Seifried (Feb 20)
- RE: Handling CVEs for the XML entity expansion issues Christey, Steven M. (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Tim (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Kurt Seifried (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Tim (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Kurt Seifried (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Tim (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Tim (Feb 20)
- RE: Handling CVEs for the XML entity expansion issues Christey, Steven M. (Feb 20)
- RE: RE: Handling CVEs for the XML entity expansion issues Christey, Steven M. (Feb 20)
- Re: RE: Handling CVEs for the XML entity expansion issues Kurt Seifried (Feb 20)