PT-2016-2122 · Php+2 · Php-Fpm+4
Publicado
2016-04-21
·
Atualizado
2022-07-20
·
CVE-2015-8866
CVSS v3.1
9.6
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.5.22
PHP versions 5.6.x prior to 5.6.6
Description
The issue is related to the ext/libxml/libxml.c file in PHP, where threads are not properly isolated when PHP-FPM is used, allowing remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document.
Recommendations
For PHP versions prior to 5.5.22, update to version 5.5.22 or later.
For PHP versions 5.6.x prior to 5.6.6, update to version 5.6.6 or later.
As a temporary workaround, consider disabling the use of
libxml disable entity loader until a patch is available.Exploit
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Php
Php-Fpm
Suse
Libxml