Bug #67350 [Opn->Fbk]: An XML DTD with an external parameter failes to include the subset

From: Date: Mon, 02 Jun 2014 17:24:45 +0000
Subject: Bug #67350 [Opn->Fbk]: An XML DTD with an external parameter failes to include the subset
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186014@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67350&edit=1 ID: 67350 Updated by: requinix@php.net Reported by: rjlaustin at teksavvy dot com Summary: An XML DTD with an external parameter failes to include the subset -Status: Open +Status: Feedback Type: Bug Package: DOM XML related Operating System: Linux PHP Version: 5.4.28 Block user comment: N Private report: N New Comment: @rjlaustin, please try @ant-dani-2's suggestion. Previous Comments: ------------------------------------------------------------------------ [2014-06-02 15:38:48] ant-dani-2 at hotmail dot com So I found out this is not really a bug, but the result of a security patch agains XXE Injection. If you're just loading a local trusted xml file, don't forget to explicitly tell libxml2 to load the external entities: $xml = new DOMDocument(); $xml->load("your.xml", LIBXML_DTDLOAD | LIBXML_DTDATTR | LIBXML_DTDVALID); This will "fix" your bug. I hope it helps you. ------------------------------------------------------------------------ [2014-06-01 22:59:10] ant-dani-2 at hotmail dot com +1 Same thing happens on my ubuntu 14.04 server with PHP Version 5.5.9-1ubuntu4 (built Apr 9 2014). Exactly same situation when including an external DTD. On my development WAMP server with PHP Version 5.5.12 (built Apr 30 2014), this bug does not occur. Not sure if the bug was fixed as of PHP Version 5.5.10 ------------------------------------------------------------------------ [2014-05-28 02:10:25] rjlaustin at teksavvy dot com Description: ------------ This problem occurs on two Linux systems where my code is used but over which I have no control and limited information. One is on version 5.4.28, built May 5 2014, the other is on 5.5.3-1, built April 4 2014. The problem did not occur on whatever versions they were running before last week. The validation of XML against a DTD fails, complaining that one or more entities has no declaration. The message is: DOMDocument::validate(): No declaration for element xxxx All the elements complained of are in subsets that are (or rather were, because I have had to change them all) included in the outer DTD by means of the external parameter notation, e.g. <!ENTITY % theatre SYSTEM "theatre.dtd"> later followed by %theatre; It appears that the contents of (in this case) "theatre.dtd" are simply lost. Putting the contents of the file inline in the outer DTD is a successful workaround. I have tested the latest Mac version of PHP available from XAMPP (5.5.11 built April 9) and it does NOT have this bug. Since I have to support my code on any system, even if this problem gets fixed I will never be able to use this feature again because I will never know when a all the potential users have moved up to the fixed release. It's an annoying loss of a convenient feature but it isn't a show-stopper. Test script: --------------- I'm afraid I am not in a position to ask the people who got the problem to restore their code so as to demonstrate it now. And I haven't got a system of my own that displays the problem. A fix will be of no use to me now, but if there is interest in getting it fixed and you need more documentation I could probably work up a little demonstration script. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67350&edit=1

« previous php.bugs (#186014) next »