VDB
Sign up
HIGH

GHSA-5v43-55m5-qr8f

getID3 is vulnerable to XML External Entity (XXE)

Quick fix

GHSA-5v43-55m5-qr8f — james-heinrich/getid3: upgrade to the fixed version with the command below.

composer require james-heinrich/getid3:^1.9.9

Details

getID3() before 1.9.9, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/james-heinrich/getid3
Introduced in: 0Fixed in: 1.9.9
Fixcomposer require james-heinrich/getid3:^1.9.9

References