summaryrefslogtreecommitdiff
path: root/build
diff options
context:
space:
mode:
authorDik Takken <d.h.j.takken@freedom.nl>2020-07-16 14:19:40 +0200
committerNikita Popov <nikita.ppv@gmail.com>2020-08-03 21:51:10 +0200
commit691a09f291a909cba8821ef16a447a5e615dee69 (patch)
tree0419088687170f2e22b1bd56b39cea705ed4e7eb /build
parent44c7128fb726696a7c23ff694d1077cf0cf435d4 (diff)
downloadphp-git-691a09f291a909cba8821ef16a447a5e615dee69.tar.gz
Bump libxml version requirement 2.7.6 => 2.9.0
Since libxml version 2.9.0 external entity loading is disabled by default. Bumping the version requirement means that XML processing in PHP is no longer vulnerable to XXE processing attacks by default.
Diffstat (limited to 'build')
-rw-r--r--build/php.m42
1 files changed, 1 insertions, 1 deletions
diff --git a/build/php.m4 b/build/php.m4
index bdc02573ac..1059d7f2f4 100644
--- a/build/php.m4
+++ b/build/php.m4
@@ -2010,7 +2010,7 @@ dnl
dnl Common setup macro for libxml.
dnl
AC_DEFUN([PHP_SETUP_LIBXML], [
- PKG_CHECK_MODULES([LIBXML], [libxml-2.0 >= 2.7.6])
+ PKG_CHECK_MODULES([LIBXML], [libxml-2.0 >= 2.9.0])
PHP_EVAL_INCLINE($LIBXML_CFLAGS)
PHP_EVAL_LIBLINE($LIBXML_LIBS, $1)