Edit report at https://bugs.php.net/bug.php?id=64938&edit=1
ID: 64938
Comment by: remi@php.net
Reported by: Sjon at hortensius dot net
Summary: libxml_disable_entity_loader setting is shared
between threads
Status: Assigned
Type: Bug
Package: *XML functions
Operating System: Archlinux
PHP Version: 5.4.15
Assigned To: remi
Block user comment: N
Private report: N
CVE-ID: 2015-8866
New Comment:
Can someone test this simple fix proposal
diff --git a/ext/libxml/libxml.c b/ext/libxml/libxml.c
index d88860c..bfc1224 100644
--- a/ext/libxml/libxml.c
+++ b/ext/libxml/libxml.c
@@ -848,7 +848,6 @@ static PHP_MINIT_FUNCTION(libxml)
if (sapi_module.name) {
static const char * const supported_sapis[] = {
"cgi-fcgi",
- "fpm-fcgi",
"litespeed",
NULL
};
Previous Comments:
------------------------------------------------------------------------
[2016-10-14 13:38:04] cmb@php.net
Re-opened according to recent user comments (thanks!)
------------------------------------------------------------------------
[2016-10-12 09:33:40] ntd at entidi dot it
The problem is still present in php-fpm 5.6.26 (debian 8.6).
Commit c1eb87ab1a2e2df1868b70cd7b8016c6147092c5 was pushed 20 months ago, so I suppose it did not
fix the problem.
------------------------------------------------------------------------
[2016-10-10 10:27:26] robert dot egginton at c3media dot co dot uk
I can confirm that I still get the issue with 7.0.11. I run my above checking script and after a few
runs all entries come out as true, so this is still not thread safe.
------------------------------------------------------------------------
[2016-07-20 11:39:42] davey@php.net
Automatic comment on behalf of martin@divbyzero.net
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c1eb87ab1a2e2df1868b70cd7b8016c6147092c5
Log: Fix bug #64938: libxml_disable_entity_loader setting is shared between threads
------------------------------------------------------------------------
[2015-12-22 12:35:54] robert dot egginton at c3media dot co dot uk
For mark at netalico dot com:
The workaround for something like Magento (not required for CE>1.9.2.0 when a workaround was
added) is to add this line to the start of your script:
if (function_exists('libxml_disable_entity_loader')) {
libxml_disable_entity_loader(false);
}
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64938
--
Edit this bug report at https://bugs.php.net/bug.php?id=64938&edit=1