Bug #62577 [PATCH]: simplexml_load_file does not file if libxml_disable_entity_loader(true)
| From: | cmb@php.net | Date: | Mon, 15 Oct 2018 10:50:01 +0000 |
| Subject: | Bug #62577 [PATCH]: simplexml_load_file does not file if libxml_disable_entity_loader(true) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217566@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62577&edit=1
ID: 62577
Patch added by: cmb@php.net
Reported by: ivan dot enderlin at hoa-project dot net
Summary: simplexml_load_file does not file if
libxml_disable_entity_loader(true)
Status: Open
Type: Bug
Package: SimpleXML related
Operating System: All
PHP Version: master-Git-2012-07-16 (Git)
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: move-entity_loader_disabled-check
Revision: 1539600601
URL: https://bugs.php.net/patch-display.php?bug=62577&patch=move-entity_loader_disabled-check&revision=1539600601
Previous Comments:
------------------------------------------------------------------------
[2018-05-22 11:12:00] phofstetter at sensational dot ch
> and if you don't give valid path, you get an error and false.
of course. But this bug is about
simplexml_load_file failing on *any* valid path if
libxml_disable_entity_loader(true) has been called.
Here's a test script. IMHO, both assert()s should pass:
<?php
file_put_contents('/tmp/test.xml',
'<doc><foo>bar</foo></doc>');
libxml_disable_entity_loader(false);
assert(simplexml_load_file('/tmp/test.xml')->foo == 'bar');
libxml_disable_entity_loader(true);
assert(simplexml_load_file('/tmp/test.xml')->foo == 'bar');
unlink('/tmp/test.xml');
------------------------------------------------------------------------
[2018-05-22 09:34:19] cojubacaso at stelliteop dot info
I don't see how this is a bug, the function is called "simplexml_load_file", so the
expected behavior is that it will load content of a file, and if you don't give valid path, you
get an error and false.
It is also documented like that, so please just close this, changing this behavior will probably
brake a lot of applications also.
------------------------------------------------------------------------
[2016-10-17 13:32:58] cmb@php.net
Related To: Bug #73328
------------------------------------------------------------------------
[2016-10-03 20:22:58] gudang at gmail dot com
@rrichards When are you going to fix this 4 years issue?
------------------------------------------------------------------------
[2014-01-29 13:03:29] phofstetter at sensational dot ch
This bug causes libxml_disable_entity_loader(true); to also disable SoapClient - likely for the same
reason. Contrary to the other options, this one is bad though because there's no workaround
(asides of not using PHP's own SoapClient).
So as it stands now users either have to live with an annoying security hole when parsing untrusted
XML (which does happen at times) or with a defunct SOAP client plus the nice fopen wrappers not
working for all XML related functions.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62577
--
Edit this bug report at https://bugs.php.net/bug.php?id=62577&edit=1