Summary
The remote host is missing an update to zendframework announced via advisory DSA 2505-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202505-1
Insight
An XML External Entities inclusion vulnerability was discovered in Zend Framework, a PHP library. This vulnerability may allow attackers to access to local files, depending on how the framework is used.
For the stable distribution (squeeze), this problem has been fixed in version 1.10.6-1squeeze1.
For the unstable distribution (sid), this problem has been fixed in version 1.11.12-1.
We recommend that you upgrade your zendframework packages.
Severity
Classification
-
CVE CVE-2012-3363 -
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
Related Vulnerabilities