oss-sec mailing list archives

Re: RE: Handling CVEs for the XML entity expansion issues


From: Tim Brown <tmb () 65535 com>
Date: Thu, 21 Feb 2013 13:54:19 +0000

On Thursday 21 Feb 2013 00:25:19 Kurt Seifried wrote:
On 02/20/2013 06:02 AM, Christey, Steven M. wrote:
Kurt,

I'm reviewing this issue with the rest of the cve-assign team.  We
will get back to you with an answer shortly.

- Steve

Any movement on this? I'm now sitting on a huge pile of stuff that
will need CVEs.

To declare, I put forwards a candiate on another language platform to Kurt and 
Steve which would be affected by a decision to assign CVEs for XXE capable 
libraries.  In this instance, the library has no way to disable XXE at the API 
level.  Below the surface it can use various XML parsers, both native and pure 
$language.  These do not appear to support disabling resolving entities either 
(although the middleware between the two does :/).  I'm am pinging the 
security team responsible and directing them to this thread.

Tim
-- 
Tim Brown
<mailto:tmb () 65535 com>

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: