Denial of Service Vulnerability in Zend Framework by Zend Technologies
CVE-2012-6532
Currently unrated
Key Information:
- Vendor
Zend
- Status
- Vendor
- CVE Published:
- 13 February 2013
What is CVE-2012-6532?
The Zend Framework services, including Zend_Dom, Zend_Feed, Zend_Soap, and Zend_XmlRpc versions prior to 1.11.13 and 1.12.0, are susceptible to denial of service attacks. Remote attackers can exploit this vulnerability by crafting recursive or circular references within an XML entity definition in an XML DOCTYPE declaration, leading to excessive CPU consumption and potentially crippling service availability. This type of attack, known as XML Entity Expansion (XEE), can significantly affect the performance and reliability of applications built on the Zend Framework.