Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 2 Nov 2016 15:37:58 +1030
From: Doran Moppert <>
To: oss-security <>
Subject: CVE request:  XXE in perl Image::Info and XML::Twig

Starting with this bug in XML::LibXML:

> XML-LibXML: External entities are parsed by default

.. which is an insecure default setting, probably not worthy of a CVE in

I did a brief audit of other CPAN modules in Fedora that may suffer from
XXE, which uncovered these two:

> XML-Twig: expand_external_ents fails to work as documented

This option (which defaults to 0) is supposed to control XXE parsing
documents with XML::Twig, but it has no effect and XXE always takes

No fix is available yet, and my perl isn't up to proposing a sensible

XML::Twig 1.49 does feature an undocumented option 'NoXxe' which can be
used to prevent entity expansion, but that option isn't present in 1.50
(current development branch) or in earlier versions (up to 1.44) I have

> Image-Info: XXE in SVG files

This was promptly fixed in 1.38_50 / 1.39.

Doran Moppert
Red Hat Product Security

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.