{"id":"UBUNTU-CVE-2014-1626","details":"XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.","modified":"2025-07-16T07:17:14.514297Z","published":"2014-01-26T01:55:00Z","withdrawn":"2025-07-18T16:42:59Z","upstream":["CVE-2014-1626"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1626"},{"type":"REPORT","url":"http://sourceforge.net/p/marcpm/code/ci/cf2d36597a56eeeffd53b38182b8557c7bf569ac/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2014-1626"}],"affected":[{"package":{"name":"libmarc-xml-perl","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/libmarc-xml-perl@1.0.2-1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2-1"}]}],"versions":["1.0.1-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libmarc-xml-perl","binary_version":"1.0.2-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1626.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}