Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1ncDM5LWg5YzItcXc3Oc4AATUL

Several Zend Products Vulnerable to XXE and XEE attacks

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity (XXE) attacks via an XML external entity declaration in conjunction with an entity reference. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.

Permalink: https://github.com/advisories/GHSA-gp39-h9c2-qw79
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncDM5LWg5YzItcXc3Oc4AATUL
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 8 months ago


Identifiers: GHSA-gp39-h9c2-qw79, CVE-2014-2682
References: Blast Radius: 0.0

Affected Packages

packagist:zendframework/zendservice-api
Dependent packages: 5
Dependent repositories: 12
Downloads: 38,955 total
Affected Version Ranges: < 1.0.0
Fixed in: 1.0.0
All affected versions:
All unaffected versions: 1.0.0, 2.0.0
packagist:zendframework/zendservice-amazon
Dependent packages: 2
Dependent repositories: 37
Downloads: 262,610 total
Affected Version Ranges: < 2.0.3
Fixed in: 2.0.3
All affected versions: 2.0.0, 2.0.1, 2.0.2
All unaffected versions: 2.0.3, 2.0.4, 2.1.0, 2.2.0, 2.3.0, 2.3.1
packagist:zendframework/zendservice-windowsazure
Dependent packages: 0
Dependent repositories: 6
Downloads: 236 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-technorati
Dependent packages: 0
Dependent repositories: 4
Downloads: 93 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-slideshare
Dependent packages: 0
Dependent repositories: 4
Downloads: 15,713 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-nirvanix
Dependent packages: 0
Dependent repositories: 4
Downloads: 87 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendservice-audioscrobbler
Dependent packages: 0
Dependent repositories: 4
Downloads: 49 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendrest
Dependent packages: 7
Dependent repositories: 34
Downloads: 449,342 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendopenid
Dependent packages: 2
Dependent repositories: 9
Downloads: 15,808 total
Affected Version Ranges: < 2.0.2
Fixed in: 2.0.2
All affected versions: 2.0.0, 2.0.1
All unaffected versions: 2.0.2
packagist:zendframework/zendframework1
Dependent packages: 151
Dependent repositories: 841
Downloads: 6,478,672 total
Affected Version Ranges: < 1.12.4
Fixed in: 1.12.4
All affected versions: 1.12.0, 1.12.1, 1.12.2, 1.12.3
All unaffected versions: 1.12.4, 1.12.5, 1.12.6, 1.12.7, 1.12.8, 1.12.9, 1.12.10, 1.12.11, 1.12.12, 1.12.13, 1.12.14, 1.12.15, 1.12.16, 1.12.17, 1.12.18, 1.12.19, 1.12.20