Denial of Service Vulnerability in Zend Framework by Zend Technologies
CVE-2012-6532

Currently unrated

Key Information:

Vendor

Zend

Vendor
CVE Published:
13 February 2013

What is CVE-2012-6532?

The Zend Framework services, including Zend_Dom, Zend_Feed, Zend_Soap, and Zend_XmlRpc versions prior to 1.11.13 and 1.12.0, are susceptible to denial of service attacks. Remote attackers can exploit this vulnerability by crafting recursive or circular references within an XML entity definition in an XML DOCTYPE declaration, leading to excessive CPU consumption and potentially crippling service availability. This type of attack, known as XML Entity Expansion (XEE), can significantly affect the performance and reliability of applications built on the Zend Framework.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.