CVE-2014-5265
published 2014-08-18CVE-2014-5265: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.09%
86.2th percentile
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected
102 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 3.9.2+dfsg-1 (bookworm) | wordpress 3.9.2+dfsg-1 (bookworm) |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-5266: wordpress - The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal ...
vendor_debian·2014·CVSS 5.0
CVE-2014-5266 [MEDIUM] CVE-2014-5266: wordpress - The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal ...
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1)
forky: resolved (fixed in 3.9.2+dfsg-1)
sid: resolved (fixed in 3.9.2+dfsg-1)
trixie: resolved (fixed in 3.9.2+dfsg-1)
Debian
CVE-2014-5265: wordpress - The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal ...
vendor_debian·2014·CVSS 6.5
CVE-2014-5265 [MEDIUM] CVE-2014-5265: wordpress - The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal ...
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1)
forky: resolved (fixed in 3.9.2+dfsg-1)
sid: resolved (fixed in 3.9.2+dfsg-1)
trixie: resolved (fixed in 3.9.2+dfsg-1)
GHSA
GHSA-94p2-4f88-99g7: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
ghsa_unreviewed·2022-05-17·CVSS 6.5
CVE-2014-5265 [MEDIUM] GHSA-94p2-4f88-99g7: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
GHSA
GHSA-mqgc-42gw-w5hm: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2014-5266 [MEDIUM] GHSA-mqgc-42gw-w5hm: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
OSV
CVE-2014-5266: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
osv·2014-08-18·CVSS 5.0
CVE-2014-5266 [MEDIUM] CVE-2014-5266: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
OSV
CVE-2014-5265: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
osv·2014-08-18·CVSS 6.5
CVE-2014-5265 [MEDIUM] CVE-2014-5265: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5265 CVE-2014-5266 CVE-2014-5267 drupal: denial of service issue (SA-CORE-2014-004)
bugzilla·2014-08-07·CVSS 5.0
CVE-2014-5265 [MEDIUM] CVE-2014-5265 CVE-2014-5266 CVE-2014-5267 drupal: denial of service issue (SA-CORE-2014-004)
CVE-2014-5265 CVE-2014-5266 CVE-2014-5267 drupal: denial of service issue (SA-CORE-2014-004)
The upstream Drupal 6.33 and 7.31 releases fix the following issue:
""
Drupal 6 and Drupal 7 include an XML-RPC endpoint which is publicly available (xmlrpc.php). The PHP XML parser used by this XML-RPC endpoint is vulnerable to an XML entity expansion attack and other related XML payload attacks which can cause CPU and memory exhaustion and the site's database to reach the maximum number of open connections. Any of these may lead to the site becoming unavailable or unresponsive (denial of service).
All Drupal sites are vulnerable to this attack whether XML-RPC is used or not.
In addition, a similar vulnerability exists in the core OpenID module (for sites that have this module enabled).
""
Re
Bugzilla
CVE-2014-5265 CVE-2014-5266 wordpress: security issues fixed in version 3.9.2
bugzilla·2014-08-07·CVSS 5.0
CVE-2014-5265 [MEDIUM] CVE-2014-5265 CVE-2014-5266 wordpress: security issues fixed in version 3.9.2
CVE-2014-5265 CVE-2014-5266 wordpress: security issues fixed in version 3.9.2
The WordPress 3.9.2 release fixes the following security issue:
""
This release fixes a possible denial of service issue in PHP’s XML processing, reported by Nir Goldshlager of the Salesforce.com Product Security Team. It was fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team. This is the first time our two projects have coordinated joint security releases.
""
A number of other security-related issues (that may receive CVEs) were fixed in this release. Refer to the upstream announcement for further details:
https://wordpress.org/news/2014/08/wordpress-3-9-2/
CVE request:
http://www.openwall.com/lists/oss-security/2014/08/07/2
Discussion:
http://cgit.drupalcode.org/drupal/diff/includes/xmlrpc.inc?id=1849830http://www.debian.org/security/2014/dsa-2999http://www.debian.org/security/2014/dsa-3001https://core.trac.wordpress.org/changeset/29404https://wordpress.org/news/2014/08/wordpress-3-9-2/https://www.drupal.org/SA-CORE-2014-004http://cgit.drupalcode.org/drupal/diff/includes/xmlrpc.inc?id=1849830http://www.debian.org/security/2014/dsa-2999http://www.debian.org/security/2014/dsa-3001https://core.trac.wordpress.org/changeset/29404https://wordpress.org/news/2014/08/wordpress-3-9-2/https://www.drupal.org/SA-CORE-2014-004
2014-08-18
Published