Vulnerability Description
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 5.5.0, < 5.5.22 |
| Canonical | Ubuntu Linux | 12.04 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.2 |
| Suse | Linux Enterprise Module For Web Scripting | 12 |
| Suse | Linux Enterprise Software Development Kit | 12 |
Related Weaknesses (CWE)
References
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=de31324c221c1791b26350ba106cc26
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2750.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/04/24/1Mailing ListPatchThird Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/87470Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2952-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2952-2Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1509817Issue TrackingPatchThird Party Advisory
- https://bugs.php.net/bug.php?id=64938ExploitIssue TrackingPatch
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=de31324c221c1791b26350ba106cc26
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2015-8866?
CVE-2015-8866 is a vulnerability with a CVSS score of 9.6 (CRITICAL). ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote atta...
How severe is CVE-2015-8866?
CVE-2015-8866 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-8866?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php, Canonical Ubuntu Linux, Opensuse Leap, Opensuse Opensuse, Suse Linux Enterprise Module For Web Scripting.