Description
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-251-1 | zendframework security update |
Debian DLA |
DLA-251-2 | zendframework regression update |
Debian DSA |
DSA-3265-1 | zendframework security update |
Debian DSA |
DSA-3265-2 | zendframework regression update |
EUVD |
EUVD-2022-2669 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532. |
Github GHSA |
GHSA-5wm2-38q5-5rxv | Several Zend Products Vulnerable to XXE and XEE attacks |
References
History
No history.
Subscriptions
Zend
Subscribe
Zend Framework
Subscribe
Zendopenid
Subscribe
Zendrest
Subscribe
Zendservice Amazon
Subscribe
Zendservice Api
Subscribe
Zendservice Audioscrobbler
Subscribe
Zendservice Nirvanix
Subscribe
Zendservice Slideshare
Subscribe
Zendservice Technorati
Subscribe
Zendservice Windowsazure
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:21:36.135Z
Reserved: 2014-03-30T00:00:00.000Z
Link: CVE-2014-2683
No data.
Status : Deferred
Published: 2014-11-16T00:59:03.920
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2683
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA