MEDIUM
GHSA-xp8p-9rq5-4wgv
ZendXml and Zend Framework contain XXE and XEE Vulnerabilities
Quick fix
GHSA-xp8p-9rq5-4wgv — zendframework/zendframework: upgrade to the fixed version with the command below.
composer require zendframework/zendframework:^2.4.6Details
The `Zend_Xml_Security::scan` in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework
Introduced in:
2.0.0Fixed in: 2.4.6Fix
composer require zendframework/zendframework:^2.4.6Packagist/zendframework/zendframework
Introduced in:
2.5.0Fixed in: 2.5.2Fix
composer require zendframework/zendframework:^2.5.2Packagist/zendframework/zendframework1
Introduced in:
1.12.0Fixed in: 1.12.14Fix
composer require zendframework/zendframework1:^1.12.14Packagist/zendframework/zendxml
Introduced in:
1.0.0Fixed in: 1.0.1Fix
composer require zendframework/zendxml:^1.0.1Packagist/zendframework/zendframework
Introduced in:
1.12.0Fixed in: 1.12.14Fix
composer require zendframework/zendframework:^1.12.14References
- https://nvd.nist.gov/vuln/detail/CVE-2015-5161[ADVISORY]
- https://github.com/zendframework/zf1/issues/393[WEB]
- https://github.com/zendframework/ZendXml/commit/79f478fa2af85ce1fc18ac132dee5aa714c3b532[WEB]
- https://github.com/zendframework/zf1/commit/ff7edddf1410b44b5ead857c02698aad9f748d1b[WEB]
- https://framework.zend.com/security/advisory/ZF2015-06[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2015-5161.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2015-5161.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendxml/CVE-2015-5161.yaml[WEB]
- https://web.archive.org/web/20200228055156/http://www.securityfocus.com/bid/76177[WEB]
- https://www.exploit-db.com/exploits/37765[WEB]
- http://framework.zend.com/security/advisory/ZF2015-06[WEB]
- http://legalhackers.com/advisories/zend-framework-XXE-vuln.txt[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164409.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165147.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165173.html[WEB]
- http://packetstormsecurity.com/files/133068/Zend-Framework-2.4.2-1.12.13-XXE-Injection.html[WEB]
- http://seclists.org/fulldisclosure/2015/Aug/46[WEB]
- http://www.debian.org/security/2015/dsa-3340[WEB]
- http://www.securityfocus.com/bid/76177[WEB]