PT-2016-2122 · Php+2 · Php-Fpm+4

Published

2016-04-21

·

Updated

2022-07-20

·

CVE-2015-8866

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.5.22 PHP versions 5.6.x prior to 5.6.6
Description The issue is related to the ext/libxml/libxml.c file in PHP, where threads are not properly isolated when PHP-FPM is used, allowing remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document.
Recommendations For PHP versions prior to 5.5.22, update to version 5.5.22 or later. For PHP versions 5.6.x prior to 5.6.6, update to version 5.6.6 or later. As a temporary workaround, consider disabling the use of libxml disable entity loader until a patch is available.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1138
BDU:2016-01475
CVE-2015-8866
DLA-499-1
OPENSUSE-SU-2016_1274-1
OPENSUSE-SU-2016_1373-1
RHSA-2016:2750
SUSE-SU-2016:1277-1
SUSE-SU-2016:1310-1
SUSE-SU-2016:1581-1
SUSE-SU-2016:1638-1
SUSE-SU-2016_1277-1
SUSE-SU-2016_1310-1
USN-2952-1

Affected Products

Alt Linux
Php
Php-Fpm
Suse
Libxml