Improper Neutralization of Special Elements in Output Used by a Downstream Component in Zend Framework - CVE-2015-3154

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Zend Framework - CVE-2015-3154

Published: January 27, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30424
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3154
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

CRLF injection vulnerability in ZendMail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.


Affected software

Zend Framework
Amazon Linux AMI
Fedora
php-ZendFramework
php-ZendFramework2

How to mitigate CVE-2015-3154

Install update from vendor's website.

Zend Framework - update to 2.4.1
php-ZendFramework - addressed in versions 1.12.13-1.el6, 1.12.13-1.el7, 1.12.13-1.fc21, 1.12.13-1.fc22
php-ZendFramework2 - update to 2.3.9-1.el7

External References

Related Security Bulletins