[libxml2] Prevent unwanted external entity reference



commit 90ccb58242866b0ba3edbef8fe44214a101c2b3e
Author: Neel Mehta <nmehta google com>
Date:   Fri Apr 7 17:43:02 2017 +0200

    Prevent unwanted external entity reference
    
    For https://bugzilla.gnome.org/show_bug.cgi?id=780691
    
    * parser.c: add a specific check to avoid PE reference

 parser.c |    9 +++++++++
 1 files changed, 9 insertions(+), 0 deletions(-)
---
diff --git a/parser.c b/parser.c
index 609a270..c2c812d 100644
--- a/parser.c
+++ b/parser.c
@@ -8123,6 +8123,15 @@ xmlParsePEReference(xmlParserCtxtPtr ctxt)
            if (xmlPushInput(ctxt, input) < 0)
                return;
        } else {
+           if ((entity->etype == XML_EXTERNAL_PARAMETER_ENTITY) &&
+               ((ctxt->options & XML_PARSE_NOENT) == 0) &&
+               ((ctxt->options & XML_PARSE_DTDVALID) == 0) &&
+               ((ctxt->options & XML_PARSE_DTDLOAD) == 0) &&
+               ((ctxt->options & XML_PARSE_DTDATTR) == 0) &&
+               (ctxt->replaceEntities == 0) &&
+               (ctxt->validate == 0))
+               return;
+
            /*
             * TODO !!!
             * handle the extra spaces added before and after


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]