CVE-2012-3363
Summary
| CVE | CVE-2012-3363 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-13 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack. |
Risk And Classification
Primary CVSS: v3.1 9.1 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-611 | n/a | CWE-611 CWE-611 Improper Restriction of XML External Entity Reference
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | ADP | DECLARED | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 2.0 | [email protected] | Primary | 6.4 | AV:N/AC:L/Au:N/C:P/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 17 | All | All | All |
| Operating System | Fedoraproject | Fedora | 18 | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc1 | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc2 | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc3 | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: XXE in Zend | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Moodle.org: MSA-13-0016: External Entity Injection through Zend library | af854a3a-2127-422b-91ae-364da2661108 | moodle.org | Third Party Advisory |
| Debian -- Security Information -- DSA-2505-1 zendframework | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List |
| Official Moodle git projects - moodle.git/search | af854a3a-2127-422b-91ae-364da2661108 | git.moodle.org | Patch |
| Zend Framework XML Entity Processing Flaw Lets Remote Users View Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| oss-security - Moodle security notifications public | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| 404 - Page not found! - SEC Consult | af854a3a-2127-422b-91ae-364da2661108 | www.sec-consult.com | Broken Link |
| [SECURITY] Fedora 18 Update: moodle-2.3.6-1.fc18 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List |
| oss-security - Re: XXE in Zend | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| [SECURITY] Fedora 17 Update: moodle-2.2.9-1.fc17 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List |
| oss-security - XXE in Zend | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| ZF2012-01: Local file disclosure via XXE injection in Zend_XmlRpc - Advisories - Security - Zend Framework | af854a3a-2127-422b-91ae-364da2661108 | framework.zend.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996690 PHP (Composer) Security Update for zendframework/zendframework1 (GHSA-7pg4-5233-82jv)