PT-2013-1828 · Zend · Zend Framework

Yury Dyachenko

·

Publicado

2013-05-02

·

Atualizado

2022-05-17

·

CVE-2012-5657

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zend Framework versions 1.11.x through 1.11.14 Zend Framework versions 1.12.x through 1.12.0
Description The issue allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service due to CPU and memory consumption via an XML External Entity (XXE) attack. This is achieved by exploiting the Zend Feed Rss and Zend Feed Atom classes in Zend Feed.
Recommendations For versions 1.11.x through 1.11.14, update to version 1.11.15 or later. For versions 1.12.x through 1.12.0, update to version 1.12.1 or later.

Correção

DoS

Information Disclosure

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5657
DSA-2602-1
DSA-3265-1
DSA-3265-2
GHSA-9M5V-VQ4F-MRVF

Produtos afetados

Zend Framework