Edit report at https://bugs.php.net/bug.php?id=64938&edit=1
ID: 64938
Updated by: cmb@php.net
Reported by: Sjon at hortensius dot net
Summary: libxml_disable_entity_loader setting is shared
between threads
-Status: Closed
+Status: Re-Opened
Type: Bug
Package: *XML functions
Operating System: Archlinux
PHP Version: 5.4.15
Assigned To: remi
Block user comment: N
Private report: N
CVE-ID: 2015-8866
New Comment:
Re-opened according to recent user comments (thanks!)
Previous Comments:
------------------------------------------------------------------------
[2016-10-12 09:33:40] ntd at entidi dot it
The problem is still present in php-fpm 5.6.26 (debian 8.6).
Commit c1eb87ab1a2e2df1868b70cd7b8016c6147092c5 was pushed 20 months ago, so I suppose it did not
fix the problem.
------------------------------------------------------------------------
[2016-10-10 10:27:26] robert dot egginton at c3media dot co dot uk
I can confirm that I still get the issue with 7.0.11. I run my above checking script and after a few
runs all entries come out as true, so this is still not thread safe.
------------------------------------------------------------------------
[2016-07-20 11:39:42] davey@php.net
Automatic comment on behalf of martin@divbyzero.net
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c1eb87ab1a2e2df1868b70cd7b8016c6147092c5
Log: Fix bug #64938: libxml_disable_entity_loader setting is shared between threads
------------------------------------------------------------------------
[2015-12-22 12:35:54] robert dot egginton at c3media dot co dot uk
For mark at netalico dot com:
The workaround for something like Magento (not required for CE>1.9.2.0 when a workaround was
added) is to add this line to the start of your script:
if (function_exists('libxml_disable_entity_loader')) {
libxml_disable_entity_loader(false);
}
------------------------------------------------------------------------
[2015-12-22 12:26:24] robert dot egginton at c3media dot co dot uk
I'm using 5.5.30 and php-fpm and can reproduce the problem by using the inverse of the script:
Test script:
---------------
<?php
die(var_dump(libxml_disable_entity_loader(true)));
---------------
The default seems to be false for me. After a few hits the results all end up true, so somehow this
value is persisting within php-fpm children.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64938
--
Edit this bug report at https://bugs.php.net/bug.php?id=64938&edit=1