Information Exposure The advisory has been revoked - it doesn't affect any version of package zendframework  (opens in a new tab)


Threat Intelligence

EPSS
0.29% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1710-ZENDFRAMEWORK-671113
  • published2 May 2013
  • disclosed2 May 2013

Introduced: 2 May 2013

CVE-2012-5657  (opens in a new tab)
CWE-200  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:17.10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream zendframework package and not the zendframework package as distributed by Ubuntu.

The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.