Re: Disabling External Entities in libxml By Default

From: Date: Thu, 30 Jul 2015 21:46:59 +0000
Subject: Re: Disabling External Entities in libxml By Default
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-87421@lists.php.net to get a copy of this message
On 30 July 2015 19:25:47 BST, Anthony Ferrara <ircmaxell@gmail.com> wrote: > I thought SOAP was dead already. Tell that to the "Enterprises" who drag and drop in Visual Studio to create useless wrappers around hand-written XML because that's their definition of "web service". :P I don't fully understand where this vulnerability kicks in (other than <! ENTITY> which I don't think I've ever needed to consume) but any change in default behaviour needs to account for real-life usage, or it will simply become standard practice to switch it back to "insecure" mode. Regards, -- Rowan Collins [IMSoP]

« previous php.internals (#87421) next »