PHP 'ext/soap/php_xml.c 'Multiple Arbitrary File leakage Vulnerability
Release date:
Updated on: 2013-03-31
Affected Systems:
PHP 5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58766
CVE (CAN) ID: CVE-2013-1643
PHP is an embedded HTML language.
The SOAP parser in PHP versions earlier than 5.3.22 and 5.4.12 has a security vulnerability that allows remote attackers to read arbitrary files through the constructed soap wsdl file. This file contains XML External Entity declarations and object indexes. The problem handling process is related to the XML External Entity (XXE) Issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 918187
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net