-
Notifications
You must be signed in to change notification settings - Fork 7.8k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
UAF DOM\XMLDocument xinclude #17467
Comments
@YuanchengJiang You found an old libxml bug, not a PHP bug. This libxml bug was fixed in GNOME/libxml2@5a19e21 . It appears your distro has an older version of libxml and has not backported that commit. |
This issue was found and fixed in libxml2 when improving handling of malloc failures. I didn't realize at the time that it can also arise without a malloc failure. It was fixed in 2.11.0, but older versions are still vulnerable. |
Thanks Nick! |
CVE-2022-49043 has been assigned. |
Description
The following code:
Resulted in this output:
PHP Version
nightly
Operating System
No response
The text was updated successfully, but these errors were encountered: