CVE-2012-3363
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 50.25% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- zend/zend framework · fedoraproject/fedora · debian/debian linux
- Source
- secalert@redhat.com
References
- http://framework.zend.com/security/advisory/ZF2012-01Vendor Advisory
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.htmlMailing List
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.htmlMailing List
- http://openwall.com/lists/oss-security/2013/03/25/2Mailing List
- http://www.debian.org/security/2012/dsa-2505Mailing List
- http://www.openwall.com/lists/oss-security/2012/06/26/2Mailing List
- http://www.openwall.com/lists/oss-security/2012/06/26/4Mailing List
- http://www.openwall.com/lists/oss-security/2012/06/27/2Mailing List
- http://www.securitytracker.com/id?1027208Broken Link, Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=225345Third Party Advisory
- https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txtBroken Link
- http://framework.zend.com/security/advisory/ZF2012-01Vendor Advisory
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.htmlMailing List
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.htmlMailing List
- http://openwall.com/lists/oss-security/2013/03/25/2Mailing List
- http://www.debian.org/security/2012/dsa-2505Mailing List
- http://www.openwall.com/lists/oss-security/2012/06/26/2Mailing List
- http://www.openwall.com/lists/oss-security/2012/06/26/4Mailing List
- http://www.openwall.com/lists/oss-security/2012/06/27/2Mailing List
- http://www.securitytracker.com/id?1027208Broken Link, Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=225345Third Party Advisory
- https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txtBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.