Zend Framework 'zend _ XmlRpc 'Information Leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Zend Framework 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54192
Zend Framework (ZF) is an open-source PHP5 development Framework that can be used to develop web programs and services.
When Zend Framework 1.11.12 and 1.12.0 process XML data, there is an error in the "Zend_XmlRpc" class. by sending specially crafted XML data that contains external entity references, the content of some local files may be leaked.
<* Source: Johannes Greil (j.greil@sec-consult.com)
Link: http://secunia.com/advisories/49665/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Zend
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.zend.com/downloads