Open-Xchange AppSuite XML external entity information leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Open-xchange Open-Xchange Server 7.4.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65015
CVE (CAN) ID: CVE-2013-7140
Open-Xchange Server is a part of Open-source projects that mainly develop collaborative software, such as email and calendar.
Open-Xchange AppSuite 7.4.1 and earlier versions use forged requests for the CalDAV interface, which can cause file content leakage in the server system. The default value is used for the SAX generator of the XML Entity deserialization on the WebDAV interface, which can cause XXE attacks.
<* Source: Open-Xchange
Link: http://www.securityfocus.com/archive/1/530804
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
Avoid opening suspicious email attachments or files.
Vendor patch:
Open-xchange
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.open-xchange.com/home.html