PT-2024-39449 · Zend · Zend Server

Published

2024-10-22

·

Updated

2024-10-23

·

CVE-2024-9129

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zend Server versions 8.5 through 9.2
Description A format string injection issue was discovered in Zend Server. This issue was reported by Dylan Marino.
Recommendations For versions 8.5 through 9.2, update to a version newer than 9.2 to resolve the issue. At the moment, there is no information about other specific mitigation measures for this issue.

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9129

Affected Products

Zend Server