PT-2013-5145 · Php+1 · Php Openid Library+1

Kousuke Ebihara

·

Published

2013-08-21

·

Updated

2022-05-17

·

CVE-2013-4701

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP OpenID Library version 2.2.2 and earlier
Description The issue allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Recommendations For PHP OpenID Library version 2.2.2 and earlier, update to a version later than 2.2.2 to resolve the issue.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4701
GHSA-5QP6-78PR-GV8C
MGASA-2013-0272
OPENSUSE-SU-2016_2025-1

Affected Products

Php Openid Library
Suse