diff options
author | Dik Takken <d.h.j.takken@freedom.nl> | 2020-07-16 14:19:40 +0200 |
---|---|---|
committer | Nikita Popov <nikita.ppv@gmail.com> | 2020-08-03 21:51:10 +0200 |
commit | 691a09f291a909cba8821ef16a447a5e615dee69 (patch) | |
tree | 0419088687170f2e22b1bd56b39cea705ed4e7eb /build | |
parent | 44c7128fb726696a7c23ff694d1077cf0cf435d4 (diff) | |
download | php-git-691a09f291a909cba8821ef16a447a5e615dee69.tar.gz |
Bump libxml version requirement 2.7.6 => 2.9.0
Since libxml version 2.9.0 external entity loading is disabled by default.
Bumping the version requirement means that XML processing in PHP is no
longer vulnerable to XXE processing attacks by default.
Diffstat (limited to 'build')
-rw-r--r-- | build/php.m4 | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/build/php.m4 b/build/php.m4 index bdc02573ac..1059d7f2f4 100644 --- a/build/php.m4 +++ b/build/php.m4 @@ -2010,7 +2010,7 @@ dnl dnl Common setup macro for libxml. dnl AC_DEFUN([PHP_SETUP_LIBXML], [ - PKG_CHECK_MODULES([LIBXML], [libxml-2.0 >= 2.7.6]) + PKG_CHECK_MODULES([LIBXML], [libxml-2.0 >= 2.9.0]) PHP_EVAL_INCLINE($LIBXML_CFLAGS) PHP_EVAL_LIBLINE($LIBXML_LIBS, $1) |