CVE-2015-8866
22.05.2016, 01:59
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 5.5.0 ≤ 𝑥 < 5.5.22 |
php | php | 5.6.0 ≤ 𝑥 < 5.6.6 |
php | php | 7.0.0 ≤ 𝑥 < 7.0.27 |
php | php | 7.1.0 ≤ 𝑥 < 7.1.13 |
php | php | 7.2.0 ≤ 𝑥 < 7.2.1 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.10 |
opensuse | leap | 42.1 |
opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References