1
From: Daniel Veillard <veillard@redhat.com>
2
Date: Tue, 22 Apr 2014 15:30:56 +0800
3
Subject: Do not fetch external parameter entities
5
Unless explicitely asked for when validating or replacing entities
6
with their value. Problem pointed out by Daniel Berrange <berrange@redhat.com>
8
parser.c | 14 ++++++++++++++
9
1 file changed, 14 insertions(+)
11
diff --git a/parser.c b/parser.c
12
index 7381a78..8aad7b4 100644
15
@@ -2595,6 +2595,20 @@ xmlParserHandlePEReference(xmlParserCtxtPtr ctxt) {
19
+ * Note: external parsed entities will not be loaded, it is
20
+ * not required for a non-validating parser, unless the
21
+ * option of validating, or substituting entities were
22
+ * given. Doing so is far more secure as the parser will
23
+ * only process data coming from the document entity by
26
+ if ((entity->etype == XML_EXTERNAL_PARAMETER_ENTITY) &&
27
+ ((ctxt->options & XML_PARSE_NOENT) == 0) &&
28
+ ((ctxt->options & XML_PARSE_DTDVALID) == 0) &&
29
+ (ctxt->validate == 0))
33
* handle the extra spaces added before and after
34
* c.f. http://www.w3.org/TR/REC-xml#as-PE
35
* this is done independently.