PT-2013-1828 · Zend · Zend Framework
Yury Dyachenko
·
Publicado
2013-05-02
·
Atualizado
2022-05-17
·
CVE-2012-5657
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zend Framework versions 1.11.x through 1.11.14
Zend Framework versions 1.12.x through 1.12.0
Description
The issue allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service due to CPU and memory consumption via an XML External Entity (XXE) attack. This is achieved by exploiting the Zend Feed Rss and Zend Feed Atom classes in Zend Feed.
Recommendations
For versions 1.11.x through 1.11.14, update to version 1.11.15 or later.
For versions 1.12.x through 1.12.0, update to version 1.12.1 or later.
Correção
DoS
Information Disclosure
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zend Framework