PT-2016-2122 · Php+2 · Php-Fpm+4
Published
2016-04-21
·
Updated
2022-07-20
·
CVE-2015-8866
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.5.22
PHP versions 5.6.x prior to 5.6.6
Description
The issue is related to the ext/libxml/libxml.c file in PHP, where threads are not properly isolated when PHP-FPM is used, allowing remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document.
Recommendations
For PHP versions prior to 5.5.22, update to version 5.5.22 or later.
For PHP versions 5.6.x prior to 5.6.6, update to version 5.6.6 or later.
As a temporary workaround, consider disabling the use of
libxml disable entity loader until a patch is available.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Php
Php-Fpm
Suse
Libxml