Bug #62577 [Com]: simplexml_load_file does not file if libxml_disable_entity_loader(true)

From: Date: Mon, 03 Oct 2016 20:23:02 +0000
Subject: Bug #62577 [Com]: simplexml_load_file does not file if libxml_disable_entity_loader(true)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204431@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62577&edit=1

 ID:                 62577
 Comment by:         gudang at gmail dot com
 Reported by:        ivan dot enderlin at hoa-project dot net
 Summary:            simplexml_load_file does not file if
                     libxml_disable_entity_loader(true)
 Status:             Assigned
 Type:               Bug
 Package:            SimpleXML related
 Operating System:   All
 PHP Version:        master-Git-2012-07-16 (Git)
 Assigned To:        rrichards
 Block user comment: N
 Private report:     N

 New Comment:

@rrichards When are you going to fix this 4 years issue?


Previous Comments:
------------------------------------------------------------------------
[2014-01-29 13:03:29] phofstetter at sensational dot ch

This bug causes libxml_disable_entity_loader(true); to also disable SoapClient - likely for the same
reason. Contrary to the other options, this one is bad though because there's no workaround
(asides of not using PHP's own SoapClient).

So as it stands now users either have to live with an annoying security hole when parsing untrusted
XML (which does happen at times) or with a defunct SOAP client plus the nice fopen wrappers not
working for all XML related functions.

------------------------------------------------------------------------
[2014-01-27 16:44:20] phofstetter at sensational dot ch

External entity loading in XML is problematic security-wise (see https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing
and for example http://www.ubercomp.com/posts/2014-01-16_facebook_remote_code_execution
where Facebook was hit by that).

It's generally advised to turn off external entity loading.

But because of this bug, turning that off also turns off *all* external file loading via libxml. 

What we need IMHO is something that turns off loading files in response to parsing untrusted XML.
Requesting XML from an external source in itself isn't a problem.

If this current behaviour is intended, please consider adding a note to the documentation explaining
the case and telling users to use fopen (though that means that it's no longer possible to work
with a huge stream of XML data because libxml_disable_entity_loader() also disables
XmlReader::open()

------------------------------------------------------------------------
[2013-12-15 01:19:07] claudio dot mulas at lucla dot net

Finally i've found what's the problem on my website. Still not fixed? :(

------------------------------------------------------------------------
[2013-08-29 07:18:51] ivan dot enderlin at hoa-project dot net

ping? Any news from the front?

------------------------------------------------------------------------
[2013-05-29 07:21:46] sjon at hortensius dot net

I can confirm this issue; it is very annoying and unexpected. Can't the code, as 
a work-around use file-get-contents + simplexml_load_string internally?

This issue is also related to bug #64938 imo

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=62577


--
Edit this bug report at https://bugs.php.net/bug.php?id=62577&edit=1


Thread (19 messages)

« previous php.bugs (#204431) next »