Improper Neutralization of Special Elements in Output Used by a Downstream Component in Zend Framework - CVE-2015-3154
Published: January 27, 2020 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
CRLF injection vulnerability in ZendMail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
Affected software
Amazon Linux AMI
Fedora
php-ZendFramework
php-ZendFramework2
How to mitigate CVE-2015-3154
php-ZendFramework - addressed in versions 1.12.13-1.el6, 1.12.13-1.el7, 1.12.13-1.fc21, 1.12.13-1.fc22
php-ZendFramework2 - update to 2.3.9-1.el7
External References
Related Security Bulletins
- Improper Neutralization of Special Elements in Output Used by a Downstream Component in Zend Framework
- Amazon Linux AMI update for php-ZendFramework
- Fedora EPEL 7 update for php-ZendFramework2
- Fedora 21 update for php-ZendFramework
- Fedora 22 update for php-ZendFramework
- Fedora EPEL 6 update for php-ZendFramework
- Fedora EPEL 7 update for php-ZendFramework