Edit report at https://bugs.php.net/bug.php?id=64938&edit=1
ID: 64938
Comment by: maunel-php at mausz dot at
Reported by: Sjon at hortensius dot net
Summary: libxml_disable_entity_loader setting is shared
between requests (FPM)
Status: Closed
Type: Bug
Package: *XML functions
Operating System: Archlinux
PHP Version: 5.4.15
Assigned To: remi
Block user comment: N
Private report: N
CVE-ID: 2015-8866
New Comment:
@remi
Just noticed that there's a bug report for this. We're shipping the following patch since
noticing the issue ourself:
diff -Naur php-7.2.0.orig/ext/libxml/libxml.c php-7.2.0/ext/libxml/libxml.c
--- php-7.2.0.orig/ext/libxml/libxml.c 2017-11-12 19:03:42.890478753 +0100
+++ php-7.2.0/ext/libxml/libxml.c 2017-11-12 19:03:58.510298201 +0100
@@ -880,13 +880,14 @@
xmlSetGenericErrorFunc(NULL, php_libxml_error_handler);
xmlParserInputBufferCreateFilenameDefault(php_libxml_input_buffer_create_filename);
xmlOutputBufferCreateFilenameDefault(php_libxml_output_buffer_create_filename);
-
- /* Enable the entity loader by default. This ensures that
- * other threads/requests that might have disabled the loader
- * do not affect the current request.
- */
- LIBXML(entity_loader_disabled) = 0;
}
+
+ /* Enable the entity loader by default. This ensures that
+ * other threads/requests that might have disabled the loader
+ * do not affect the current request.
+ */
+ LIBXML(entity_loader_disabled) = 0;
+
return SUCCESS;
}
No idea which one is better. Just wanted to share this.
Previous Comments:
------------------------------------------------------------------------
[2017-11-28 17:00:54] remi@php.net
Automatic comment on behalf of remi@remirepo.net
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8e5b9532da0308c50c9cb316e9fda530becdc543
Log: Fixed bug #64938 libxml_disable_entity_loader setting is shared between requests (FPM)
------------------------------------------------------------------------
[2017-11-27 15:59:44] remi@php.net
Can someone test this simple fix proposal
diff --git a/ext/libxml/libxml.c b/ext/libxml/libxml.c
index d88860c..bfc1224 100644
--- a/ext/libxml/libxml.c
+++ b/ext/libxml/libxml.c
@@ -848,7 +848,6 @@ static PHP_MINIT_FUNCTION(libxml)
if (sapi_module.name) {
static const char * const supported_sapis[] = {
"cgi-fcgi",
- "fpm-fcgi",
"litespeed",
NULL
};
------------------------------------------------------------------------
[2016-10-14 13:38:04] cmb@php.net
Re-opened according to recent user comments (thanks!)
------------------------------------------------------------------------
[2016-10-12 09:33:40] ntd at entidi dot it
The problem is still present in php-fpm 5.6.26 (debian 8.6).
Commit c1eb87ab1a2e2df1868b70cd7b8016c6147092c5 was pushed 20 months ago, so I suppose it did not
fix the problem.
------------------------------------------------------------------------
[2016-10-10 10:27:26] robert dot egginton at c3media dot co dot uk
I can confirm that I still get the issue with 7.0.11. I run my above checking script and after a few
runs all entries come out as true, so this is still not thread safe.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64938
--
Edit this bug report at https://bugs.php.net/bug.php?id=64938&edit=1