Name | CVE-2014-1626 |
Description | XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 736275 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
libmarc-xml-perl (PTS) | buster, bullseye | 1.0.5-1 | fixed |
bookworm, sid | 1.0.5-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
libmarc-xml-perl | source | (unstable) | 1.0.2-1 | 736275 |
[wheezy] - libmarc-xml-perl <no-dsa> (Too intrusive to backport)
[squeeze] - libmarc-xml-perl <no-dsa> (Too intrusive to backport)
http://sourceforge.net/p/marcpm/code/ci/cf2d36597a56eeeffd53b38182b8557c7bf569ac/
older versions do not have the ability to set a user custom parser, trying to fix CVE-2014-1626 not clear yet
upstream developer contacted and is looking into it; backport fix might be to intrusive due to change in used Module