PT-2017-7207 · Zend · Zend Framework+1

Adam Mariš

·

Published

2016-05-21

·

Updated

2022-05-17

·

CVE-2015-7503

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zend Framework versions prior to 2.4.9 zend-crypt versions 2.4.x prior to 2.4.9 zend-crypt versions 2.5.x prior to 2.5.2
Description The issue allows remote attackers to recover the RSA private key.
Recommendations For Zend Framework versions prior to 2.4.9, update to version 2.4.9 or later. For zend-crypt versions 2.4.x prior to 2.4.9, update to version 2.4.9 or later. For zend-crypt versions 2.5.x prior to 2.5.2, update to version 2.5.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7503
GHSA-PM9M-W23Q-5967
MGASA-2016-0196

Affected Products

Zend Framework
Zend-Crypt