CVE-2012-6531
Summary
| CVE | CVE-2012-6531 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-13 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | (1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zend | Zend Framework | 1.0.4 | All | All | All |
| Application | Zend | Zend Framework | 1.10.0 | All | All | All |
| Application | Zend | Zend Framework | 1.10.1 | All | All | All |
| Application | Zend | Zend Framework | 1.10.2 | All | All | All |
| Application | Zend | Zend Framework | 1.10.3 | All | All | All |
| Application | Zend | Zend Framework | 1.10.4 | All | All | All |
| Application | Zend | Zend Framework | 1.10.5 | All | All | All |
| Application | Zend | Zend Framework | 1.10.6 | All | All | All |
| Application | Zend | Zend Framework | 1.10.7 | All | All | All |
| Application | Zend | Zend Framework | 1.10.8 | All | All | All |
| Application | Zend | Zend Framework | 1.11.0 | All | All | All |
| Application | Zend | Zend Framework | 1.11.1 | All | All | All |
| Application | Zend | Zend Framework | 1.11.10 | All | All | All |
| Application | Zend | Zend Framework | 1.11.11 | All | All | All |
| Application | Zend | Zend Framework | 1.11.12 | All | All | All |
| Application | Zend | Zend Framework | 1.11.2 | All | All | All |
| Application | Zend | Zend Framework | 1.11.3 | All | All | All |
| Application | Zend | Zend Framework | 1.11.4 | All | All | All |
| Application | Zend | Zend Framework | 1.11.5 | All | All | All |
| Application | Zend | Zend Framework | 1.11.6 | All | All | All |
| Application | Zend | Zend Framework | 1.11.7 | All | All | All |
| Application | Zend | Zend Framework | 1.11.8 | All | All | All |
| Application | Zend | Zend Framework | 1.11.9 | All | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc1 | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc2 | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc3 | All | All |
| Application | Zend | Zend Framework | 1.12.0 | rc4 | All | All |
| Application | Zend | Zend Framework | 1.5.0 | All | All | All |
| Application | Zend | Zend Framework | 1.5.1 | All | All | All |
| Application | Zend | Zend Framework | 1.5.2 | All | All | All |
| Application | Zend | Zend Framework | 1.5.3 | All | All | All |
| Application | Zend | Zend Framework | 1.6.0 | All | All | All |
| Application | Zend | Zend Framework | 1.6.1 | All | All | All |
| Application | Zend | Zend Framework | 1.6.2 | All | All | All |
| Application | Zend | Zend Framework | 1.7.0 | All | All | All |
| Application | Zend | Zend Framework | 1.7.1 | All | All | All |
| Application | Zend | Zend Framework | 1.7.2 | All | All | All |
| Application | Zend | Zend Framework | 1.7.3 | All | All | All |
| Application | Zend | Zend Framework | 1.7.4 | All | All | All |
| Application | Zend | Zend Framework | 1.7.5 | All | All | All |
| Application | Zend | Zend Framework | 1.7.6 | All | All | All |
| Application | Zend | Zend Framework | 1.7.7 | All | All | All |
| Application | Zend | Zend Framework | 1.7.8 | All | All | All |
| Application | Zend | Zend Framework | 1.7.9 | All | All | All |
| Application | Zend | Zend Framework | 1.8.0 | All | All | All |
| Application | Zend | Zend Framework | 1.8.1 | All | All | All |
| Application | Zend | Zend Framework | 1.8.2 | All | All | All |
| Application | Zend | Zend Framework | 1.8.3 | All | All | All |
| Application | Zend | Zend Framework | 1.8.4 | All | All | All |
| Application | Zend | Zend Framework | 1.8.5 | All | All | All |
| Application | Zend | Zend Framework | 1.9.0 | All | All | All |
| Application | Zend | Zend Framework | 1.9.1 | All | All | All |
| Application | Zend | Zend Framework | 1.9.2 | All | All | All |
| Application | Zend | Zend Framework | 1.9.3 | All | All | All |
| Application | Zend | Zend Framework | 1.9.4 | All | All | All |
| Application | Zend | Zend Framework | 1.9.5 | All | All | All |
| Application | Zend | Zend Framework | 1.9.6 | All | All | All |
| Application | Zend | Zend Framework | 1.9.7 | All | All | All |
| Application | Zend | Zend Framework | 1.9.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: XXE in Zend | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian -- Security Information -- DSA-2505-1 zendframework | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 404 - Page not found! - SEC Consult | af854a3a-2127-422b-91ae-364da2661108 | www.sec-consult.com | |
| oss-security - Re: XXE in Zend | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - XXE in Zend | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| ZF2012-01: Local file disclosure via XXE injection in Zend_XmlRpc - Advisories - Security - Zend Framework | af854a3a-2127-422b-91ae-364da2661108 | framework.zend.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996671 PHP (Composer) Security Update for zendframework/zendframework1 (GHSA-h5p3-7mg6-hgj4)