php is vulnerable to XML external entity (XXE) attacks. It was found that the PHP SOAP parser allowed the expansion of external XML entities during SOAP message parsing. A remote attacker could possibly use this flaw to read arbitrary files that are accessible to a PHP application using a SOAP extension.
bugs.debian.org/cgi-bin/bugreport.cgi?bug=702221
git.php.net/?p=php-src.git;a=commit;h=8e76d0404b7f664ee6719fd98f0483f0ac4669d6
lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
lists.opensuse.org/opensuse-security-announce/2013-07/msg00034.html
lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
rhn.redhat.com/errata/RHSA-2013-1307.html
rhn.redhat.com/errata/RHSA-2013-1615.html
secunia.com/advisories/55078
support.apple.com/kb/HT5880
www.debian.org/security/2013/dsa-2639
www.mandriva.com/security/advisories?name=MDVSA-2013:114
www.php.net/ChangeLog-5.php
www.ubuntu.com/usn/USN-1761-1
access.redhat.com/security/updates/classification/#moderate
access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/5/html/5.10_Technical_Notes/php53.html#RHSA-2013-1307
bugs.gentoo.org/show_bug.cgi?id=459904
bugzilla.redhat.com/show_bug.cgi?id=837044
bugzilla.redhat.com/show_bug.cgi?id=869691
bugzilla.redhat.com/show_bug.cgi?id=869693
bugzilla.redhat.com/show_bug.cgi?id=869697
bugzilla.redhat.com/show_bug.cgi?id=892695
bugzilla.redhat.com/show_bug.cgi?id=918187
bugzilla.redhat.com/show_bug.cgi?id=951075
bugzilla.redhat.com/show_bug.cgi?id=953818
rhn.redhat.com/errata/RHSA-2013-1307.html
wiki.mageia.org/en/Support/Advisories/MGASA-2013-0101