VDB
Sign up
CRITICAL9.8

GHSA-v42g-7q2x-cw32

Zendframework1 potential SQL injection vector using null byte for PDO (MsSql, SQLite)

Quick fix

GHSA-v42g-7q2x-cw32 — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.12.16

Details

The PDO adapters of Zend Framework 1 do not filter null bytes values in SQL statements. A PDO adapter can treat null bytes in a query as a string terminator, allowing an attacker to add arbitrary SQL following a null byte, and thus create a SQL injection.

We tested and verified the null byte injection using pdo_dblib (FreeTDS) on a Linux environment to access a remote Microsoft SQL Server, and also tested against and noted the vector against pdo_sqlite.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.12.0Fixed in: 1.12.16
Fixcomposer require zendframework/zendframework1:^1.12.16

References