Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 21 Feb 2013 13:54:19 +0000
From: Tim Brown <>
Cc: Kurt Seifried <>,
 "Christey, Steven M." <>
Subject: Re: RE: Handling CVEs for the XML entity expansion issues

On Thursday 21 Feb 2013 00:25:19 Kurt Seifried wrote:
> On 02/20/2013 06:02 AM, Christey, Steven M. wrote:
> > Kurt,
> > 
> > I'm reviewing this issue with the rest of the cve-assign team.  We
> > will get back to you with an answer shortly.
> > 
> > - Steve
> Any movement on this? I'm now sitting on a huge pile of stuff that
> will need CVEs.

To declare, I put forwards a candiate on another language platform to Kurt and 
Steve which would be affected by a decision to assign CVEs for XXE capable 
libraries.  In this instance, the library has no way to disable XXE at the API 
level.  Below the surface it can use various XML parsers, both native and pure 
$language.  These do not appear to support disabling resolving entities either 
(although the middleware between the two does :/).  I'm am pinging the 
security team responsible and directing them to this thread.

Tim Brown

Download attachment "signature.asc " of type "application/pgp-signature" (837 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.