Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01d20yLTM4cTUtNXJ4ds4AATUI
Several Zend Products Vulnerable to XXE and XEE attacks
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.
Permalink: https://github.com/advisories/GHSA-5wm2-38q5-5rxvJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01d20yLTM4cTUtNXJ4ds4AATUI
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 8 months ago
Identifiers: GHSA-5wm2-38q5-5rxv, CVE-2014-2683
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-2683
- http://advisories.mageia.org/MGASA-2014-0151.html
- http://framework.zend.com/security/advisory/ZF2014-01
- http://seclists.org/oss-sec/2014/q2/0
- http://www.debian.org/security/2015/dsa-3265
- https://web.archive.org/web/20140419041226/http://www.securityfocus.com/bid/66358
- https://web.archive.org/web/20150523055201/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2014:072/?name=MDVSA-2014:072
- https://github.com/advisories/GHSA-5wm2-38q5-5rxv
Affected Packages
packagist:zendframework/zendservice-api
Dependent packages: 5Dependent repositories: 12
Downloads: 38,955 total
Affected Version Ranges: < 1.0.0
Fixed in: 1.0.0
All affected versions:
All unaffected versions: 1.0.0, 2.0.0
packagist:zendframework/zendservice-amazon
Dependent packages: 2Dependent repositories: 37
Downloads: 262,610 total
Affected Version Ranges: < 2.0.3
Fixed in: 2.0.3
All affected versions: 2.0.0, 2.0.1, 2.0.2
All unaffected versions: 2.0.3, 2.0.4, 2.1.0, 2.2.0, 2.3.0, 2.3.1
packagist:zendframework/zendservice-windowsazure
Dependent packages: 0Dependent repositories: 6
Downloads: 236 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-technorati
Dependent packages: 0Dependent repositories: 4
Downloads: 93 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-slideshare
Dependent packages: 0Dependent repositories: 4
Downloads: 15,713 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-nirvanix
Dependent packages: 0Dependent repositories: 4
Downloads: 87 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-audioscrobbler
Dependent packages: 0Dependent repositories: 4
Downloads: 49 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendrest
Dependent packages: 7Dependent repositories: 34
Downloads: 449,342 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendopenid
Dependent packages: 2Dependent repositories: 9
Downloads: 15,808 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendframework1
Dependent packages: 151Dependent repositories: 841
Downloads: 6,478,672 total
Affected Version Ranges: < 1.12.4
Fixed in: 1.12.4
All affected versions: 1.12.0, 1.12.1, 1.12.2, 1.12.3
All unaffected versions: 1.12.4, 1.12.5, 1.12.6, 1.12.7, 1.12.8, 1.12.9, 1.12.10, 1.12.11, 1.12.12, 1.12.13, 1.12.14, 1.12.15, 1.12.16, 1.12.17, 1.12.18, 1.12.19, 1.12.20