CVE-2013-1824

Description

From CVE.org

The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.

Statement

Not vulnerable. This issue did not affect any versions of PHP as shipped with any Red Hat product. Please see https://bugzilla.redhat.com/show_bug.cgi?id=918187#c5 for further details.

Frequently Asked Questions

Want to get errata notifications? Sign up here.