MEDIUM
GHSA-9m5v-vq4f-mrvf
Zend Framework XXE Vulnerability
Quick fix
GHSA-9m5v-vq4f-mrvf — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.11.15Details
The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework1
Introduced in:
0Fixed in: 1.11.15Fix
composer require zendframework/zendframework1:^1.11.15Packagist/zendframework/zendframework1
Introduced in:
1.12.0-rc1Fixed in: 1.12.1Fix
composer require zendframework/zendframework1:^1.12.1References
- https://nvd.nist.gov/vuln/detail/CVE-2012-5657[ADVISORY]
- https://github.com/zendframework/zf1/commit/15c84914f063efea49ea1c4425459a792cc185ea[WEB]
- https://github.com/zendframework/zf1[PACKAGE]
- https://web.archive.org/web/20131101014013/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2013:115/?name=MDVSA-2013:115[WEB]
- http://framework.zend.com/security/advisory/ZF2012-05[WEB]
- http://openwall.com/lists/oss-security/2012/12/20/2[WEB]
- http://openwall.com/lists/oss-security/2012/12/20/4[WEB]
- http://www.debian.org/security/2012/dsa-2602[WEB]