Date: Thu, 21 Feb 2013 13:54:19 +0000 From: Tim Brown <tmb@...35.com> To: oss-security@...ts.openwall.com Cc: Kurt Seifried <kseifried@...hat.com>, "Christey, Steven M." <coley@...re.org> Subject: Re: RE: Handling CVEs for the XML entity expansion issues On Thursday 21 Feb 2013 00:25:19 Kurt Seifried wrote: > On 02/20/2013 06:02 AM, Christey, Steven M. wrote: > > Kurt, > > > > I'm reviewing this issue with the rest of the cve-assign team. We > > will get back to you with an answer shortly. > > > > - Steve > > Any movement on this? I'm now sitting on a huge pile of stuff that > will need CVEs. To declare, I put forwards a candiate on another language platform to Kurt and Steve which would be affected by a decision to assign CVEs for XXE capable libraries. In this instance, the library has no way to disable XXE at the API level. Below the surface it can use various XML parsers, both native and pure $language. These do not appear to support disabling resolving entities either (although the middleware between the two does :/). I'm am pinging the security team responsible and directing them to this thread. Tim -- Tim Brown <mailto:tmb@...35.com> Download attachment "signature.asc " of type "application/pgp-signature" (837 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.