CVE-2015-5161

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

References

http://framework.zend.com/security/advisory/ZF2015-06

http://legalhackers.com/advisories/zend-framework-XXE-vuln.txt

http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164409.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165147.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165173.html

http://packetstormsecurity.com/files/133068/Zend-Framework-2.4.2-1.12.13-XXE-Injection.html

http://seclists.org/fulldisclosure/2015/Aug/46

http://www.debian.org/security/2015/dsa-3340

http://www.securityfocus.com/bid/76177

https://www.exploit-db.com/exploits/37765/

Details

Source: MITRE

Published: 2015-08-25

Updated: 2016-12-24

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:zend:zend_framework:1.0.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.0:rc2:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.0:rc2a:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.0:rc3:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.0.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.5.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.5.0:rc2:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.5.0:rc3:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.5.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.5.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.5.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.6.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.6.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.6.0:rc2:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.6.0:rc3:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.6.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.6.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.0:pl1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.0:pr:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.3:pl1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.7.9:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.0:a1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.0:b1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.4:pl1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.8.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.0:a1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.0:b1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.3:pl1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.9.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.0:alpha1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.0:beta1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.10.9:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.0:b1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.9:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.10:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.11:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.12:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.11.13:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.0:rc2:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.0:rc3:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.0:rc4:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.9:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.10:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.11:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.12:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:1.12.13:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc1:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc2:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc3:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc4:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc5:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc6:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.0:rc7:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.0.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.1.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.9:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.2.10:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.6:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.7:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.8:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.3.9:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.4.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.4.1:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.4.2:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.4.3:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.4.4:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.4.5:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.5.0:*:*:*:*:*:*:*

cpe:2.3:a:zend:zend_framework:2.5.1:*:*:*:*:*:*:*

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
93161SUSE SLES11 Security Update : php53 (SUSE-SU-2016:1638-1) (BACKRONYM)NessusSuSE Local Security Checks
critical
9136Zend Framework 1.x < 1.12.14 / 2.x < 2.4.6 / 2.5.x < 2.5.2 XXE InjectionNessus Network MonitorCGI
high
89458Fedora 21 : php-ZendFramework-1.12.16-1.fc21 (2015-f1e18131bc)NessusFedora Local Security Checks
high
89271Fedora 22 : php-ZendFramework-1.12.16-1.fc22 (2015-6d70a701bf)NessusFedora Local Security Checks
high
89193Fedora 23 : php-ZendFramework-1.12.16-1.fc23 (2015-2e7c06c639)NessusFedora Local Security Checks
high
85670Fedora 22 : php-ZendFramework2-2.4.7-1.fc22 / php-guzzle-Guzzle-3.9.3-5.fc22 (2015-13529)NessusFedora Local Security Checks
medium
85669Fedora 21 : php-ZendFramework2-2.4.7-1.fc21 / php-guzzle-Guzzle-3.9.3-5.fc21 (2015-13488)NessusFedora Local Security Checks
medium
85663Debian DLA-302-1 : zendframework security updateNessusDebian Local Security Checks
medium
85591Fedora 23 : php-ZendFramework2-2.4.7-1.fc23 / php-guzzle-Guzzle-3.9.3-5.fc23 (2015-13314)NessusFedora Local Security Checks
medium
85589Debian DSA-3340-1 : zendframework - security updateNessusDebian Local Security Checks
medium