CVE-2015-8866
published 2016-05-22CVE-2015-8866: ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes…
PriorityP347critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
4.03%
89.4th percentile
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| php | php | >= 5.5.0 < 5.5.22 | 5.5.22 |
| php | php | >= 5.6.0 < 5.6.6 | 5.6.6 |
| php | php | >= 7.0.0 < 7.0.27 | 7.0.27 |
| php | php | >= 7.1.0 < 7.1.13 | 7.1.13 |
| php | php | >= 7.2.0 < 7.2.1 | 7.2.1 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.16 | 5.5.9+dfsg-1ubuntu4.16 |
| suse | linux_enterprise_module_for_web_scripting | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x5qj-644j-7xc7: ext/libxml/libxml
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2015-8866 [MEDIUM] CWE-611 GHSA-x5qj-644j-7xc7: ext/libxml/libxml
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
OSV
CVE-2015-8866: ext/libxml/libxml
osv·2016-05-22·CVSS 6.8
CVE-2015-8866 [MEDIUM] CVE-2015-8866: ext/libxml/libxml
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
Red Hat
php: libxml_disable_entity_loader setting is shared between threads
vendor_redhat·2016-04-21·CVSS 6.8
CVE-2015-8866 [MEDIUM] php: libxml_disable_entity_loader setting is shared between threads
php: libxml_disable_entity_loader setting is shared between threads
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php54-php (Red Hat Software Collections) - Will not fix
Package: php55-php (Red Hat Software Collections) - Will not fix
No detection rules found.
No public exploits indexed.
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=de31324c221c1791b26350ba106cc26bad23ace9http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.openwall.com/lists/oss-security/2016/04/24/1http://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/87470http://www.ubuntu.com/usn/USN-2952-1http://www.ubuntu.com/usn/USN-2952-2https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1509817https://bugs.php.net/bug.php?id=64938http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=de31324c221c1791b26350ba106cc26bad23ace9http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.openwall.com/lists/oss-security/2016/04/24/1http://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/87470http://www.ubuntu.com/usn/USN-2952-1http://www.ubuntu.com/usn/USN-2952-2https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1509817https://bugs.php.net/bug.php?id=64938
2016-05-22
Published