CVE-2015-8866
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
- CVSS 3.1
- 9.6 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 4.03% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- php/php · canonical/ubuntu linux · opensuse/leap · opensuse/opensuse · suse/linux enterprise module for web scripting · suse/linux enterprise software development kit
- Source
- cve@mitre.org
References
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=de31324c221c1791b26350ba106cc26bad23ace9
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2750.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/04/24/1Mailing List, Patch, Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/87470Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2952-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2952-2Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1509817Issue Tracking, Patch, Third Party Advisory
- https://bugs.php.net/bug.php?id=64938Exploit, Issue Tracking, Patch, Vendor Advisory
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=de31324c221c1791b26350ba106cc26bad23ace9
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2750.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/04/24/1Mailing List, Patch, Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/87470Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2952-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2952-2Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1509817Issue Tracking, Patch, Third Party Advisory
- https://bugs.php.net/bug.php?id=64938Exploit, Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.