Bug#838097: XML::LibXML expands external entities by default

2016-09-21 Thread Salvatore Bonaccorso
Hi Bernie, On Sat, Sep 17, 2016 at 11:55:08AM +0100, P. Benie wrote: > Package: libxml-libxml-perl > Version: 2.0116+dfsg-1+deb8u1 > > When I do an enternal entity attack against a program using > XML::LibXML, it works! This was unexpected as the underying > library, libxml2, has had its

Bug#838097: XML::LibXML expands external entities by default

2016-09-17 Thread P. Benie
Package: libxml-libxml-perl Version: 2.0116+dfsg-1+deb8u1 When I do an enternal entity attack against a program using XML::LibXML, it works! This was unexpected as the underying library, libxml2, has had its defaults changed to disable external entity loading by default (as least when not