Vulnerability Description
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xml\ | \ | < 0.39, atom_project |
Related Weaknesses (CWE)
References
- https://metacpan.org/release/MIYAGAWA/XML-Atom-0.39/source/ChangesRelease NotesThird Party Advisory
- https://seclists.org/oss-sec/2012/q1/549ExploitMailing ListThird Party Advisory
- https://metacpan.org/release/MIYAGAWA/XML-Atom-0.39/source/ChangesRelease NotesThird Party Advisory
- https://seclists.org/oss-sec/2012/q1/549ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2012-1102?
CVE-2012-1102 is a vulnerability with a CVSS score of 7.5 (HIGH). It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access...
How severe is CVE-2012-1102?
CVE-2012-1102 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1102?
Check the references section above for vendor advisories and patch information. Affected products include: Xml\ \.