CVE-2012-3363
critical
CVSS v3
9.1
CVSS v2
6.4
VIR risk
9.1
Description
Zend Framework XXE Vulnerability
Predictions
Exploit likelihood
94%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284
Vendor advisory: secalert@redhat.com — http://framework.zend.com/security/advisory/ZF2012-01
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| fedora | 17 | affected | |
| fedora | 18 | affected | |
| debian | 6.0 | affected | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | zendframework/zendframework1 | >=1.0.0,<1.11.12 | 1.11.12 |
| Packagist | zendframework/zendframework1 | >=1.12.0-rc1,<1.12.0 | 1.12.0 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| zend | zend_framework | {"startIncluding":"1.0.0","endExcluding":"1.11.12"} | 1.11.12 |
| zend | zend_framework | 1.12.0 | |
References
- http://framework.zend.com/security/advisory/ZF2012-01
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.html
- http://openwall.com/lists/oss-security/2013/03/25/2
- http://www.debian.org/security/2012/dsa-2505
- http://www.openwall.com/lists/oss-security/2012/06/26/2
- http://www.openwall.com/lists/oss-security/2012/06/26/4
- http://www.openwall.com/lists/oss-security/2012/06/27/2
- http://www.securitytracker.com/id?1027208
- https://moodle.org/mod/forum/discuss.php?d=225345
- https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txt
- https://nvd.nist.gov/vuln/detail/CVE-2012-3363
- https://github.com/zendframework/zf1/commit/281a3251d71ed40a5289ec4afc355eea8e014dc5
- https://github.com/zendframework/zf1
- https://web.archive.org/web/20170223044943/http://www.securitytracker.com/id?1027208
CWEs
CWE-611
Verify integrity in audit chain (admin only). AS-IS.