CVE-2013-1824: Apple Mac OS X

Medium severity, CVSS 4.3. EPSS: 4.3% chance of exploitation in the next 30 days.

The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.

Affected products

  • Apple Mac OS X: from 10.0.0, before 10.8.5 (fixed in 10.8.5)
  • PHP PHP: before 5.3.22 (fixed in 5.3.22); from 5.4.0, before 5.4.12 (fixed in 5.4.12)
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only

Published 2013-09-16. Last modified 2026-06-16.