develooper Front page | perl.perl4lib | Postings from January 2014

SECURITY release: MARC::File::XML 1.0.2

Thread Next
Galen Charlton
January 21, 2014 17:38
SECURITY release: MARC::File::XML 1.0.2
Message ID:

I have uploaded [1] version 1.0.2 of MARC::File::XML.  This is a
security release that repairs an XML external entity (XXE)
vulnerability.  I recommend that all uses of MARC::File::XML upgrade

Here is the change log entry:

1.0.2 Tue Jan 21 17:18:37 UTC 2014
       - MARC::File::XML will now die upon parsing a record that
         declares an external entity and tries to use it. This
         prevents the potential unwanted disclosure of the contents
         of files on the server by applications that embed this module.
         If, for some reason, an application needs to process MARCXML
         records that contain external entities, set_parser() can be
         used to force the use of an XML::LibXML parser that is
         configured to process external entities.

         The issue was reported by John Lightsey.



Galen Charlton

Thread Next Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at | Group listing | About