Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3363

Overview

Vulnerability Score 6.4 6.4
CVE Id CVE-2012-3363
Last Modified 05 Dec 2013 12:15:32
Published 13 Feb 2013 12:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-3363

Summary

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

Vulnerable Systems

Application

  • Zend Framework 1.0.0

  • Zend Framework 1.0.1

  • Zend Framework 1.0.2

  • Zend Framework 1.0.3

  • Zend Framework 1.0.4

  • Zend Framework 1.10.0

  • Zend Framework 1.10.1

  • Zend Framework 1.10.2

  • Zend Framework 1.10.3

  • Zend Framework 1.10.4

  • Zend Framework 1.10.5

  • Zend Framework 1.10.6

  • Zend Framework 1.10.7

  • Zend Framework 1.10.8

  • Zend Framework 1.10.9

  • Zend Framework 1.11.0

  • Zend Framework 1.11.1

  • Zend Framework 1.11.10

  • Zend Framework 1.11.11

  • Zend Framework 1.11.2

  • Zend Framework 1.11.3

  • Zend Framework 1.11.4

  • Zend Framework 1.11.5

  • Zend Framework 1.11.6

  • Zend Framework 1.11.7

  • Zend Framework 1.11.8

  • Zend Framework 1.11.9

  • Zend Framework 1.12.0

  • Zend Framework 1.5.0

  • Zend Framework 1.5.1

  • Zend Framework 1.5.2

  • Zend Framework 1.5.3

  • Zend Framework 1.6.0

  • Zend Framework 1.6.1

  • Zend Framework 1.6.2

  • Zend Framework 1.7.0

  • Zend Framework 1.7.1

  • Zend Framework 1.7.2

  • Zend Framework 1.7.3

  • Zend Framework 1.7.4

  • Zend Framework 1.7.5

  • Zend Framework 1.7.6

  • Zend Framework 1.7.7

  • Zend Framework 1.7.8

  • Zend Framework 1.7.9

  • Zend Framework 1.8.0

  • Zend Framework 1.8.1

  • Zend Framework 1.8.2

  • Zend Framework 1.8.3

  • Zend Framework 1.8.4

  • Zend Framework 1.8.5

  • Zend Framework 1.9.0

  • Zend Framework 1.9.1

  • Zend Framework 1.9.2

  • Zend Framework 1.9.3

  • Zend Framework 1.9.4

  • Zend Framework 1.9.5

  • Zend Framework 1.9.6

  • Zend Framework 1.9.7

  • Zend Framework 1.9.8


References

MISC - https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txt

MLIST - [oss-security] 20120627 Re: XXE in Zend

MLIST - [oss-security] 20120626 Re: XXE in Zend

MLIST - [oss-security] 20120626 XXE in Zend

DEBIAN - DSA-2505

CONFIRM - http://framework.zend.com/security/advisory/ZF2012-01

SECTRACK - 1027208

CONFIRM - https://moodle.org/mod/forum/discuss.php?d=225345

MLIST - [oss-security] 20130325 Moodle security notifications public

CONFIRM - http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284

FEDORA - FEDORA-2013-4387

FEDORA - FEDORA-2013-4404


Last Updated: 27 May 2016 11:01:52