CVE-2009-4417: Medium severity zend framework vulnerability
Published Dec 24, 2009
·Updated
The shutdown function in the ZendLogWriterMail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."
Affected Software
61 affected components
Zend Framework=0.9.0-beta
Zend Framework=1.7.3
Zend Framework=1.9.0-beta_1
Zend Framework=1.9.2
Zend Framework=1.7.5
Zend Framework=1.0.0
Zend Framework=0.1.3-preview
Zend Framework=1.5.2
Zend Framework=0.9.1-beta
Zend Framework=0.8.0-preview
Zend Framework=1.9.0-alpha_1
Zend Framework=1.0.0-rc1
Zend Framework=1.5.1
Zend Framework=1.7.7
Zend Framework=1.0.1
Zend Framework=1.5.3
Zend Framework=1.9
Zend Framework=1.7.2
Zend Framework=1.7.8
Zend Framework=0.1.5-preview
Zend Framework<=1.9.6
Zend Framework=1.0.0-rc3
Zend Framework=1.9.0-rc1
Zend Framework=1.5.0
Zend Framework=1.7.1
Zend Framework=1.5.0-rc1
Zend Framework=1.8.0-alpha_1
Zend Framework=1.0.0-rc2
Zend Framework=1.7.0
Zend Framework=1.6.0-rc3
Zend Framework=1.6.2
Zend Framework=1.8.3
Zend Framework=1.6.0-rc2
Zend Framework=1.5.0-rc2
Zend Framework=1.9.5
Zend Framework=1.5.0-rc3
Zend Framework=1.8.2
Zend Framework=1.8.0-beta_1
Zend Framework=1.8.0
Zend Framework=1.6.1
Zend Framework=1.0.2
Zend Framework=1.7.0-preview
Zend Framework=1.7.6
Zend Framework=1.9.1
Zend Framework=1.0.4
Zend Framework=0.9.2-beta
Zend Framework=1.9.0
Zend Framework=0.9.3-beta
Zend Framework=1.6.0
Zend Framework=1.8.1
Zend Framework=1.7.4
Zend Framework=0.6.0-preview
Zend Framework=1.9.3
Zend Framework=0.1.4-preview
Zend Framework=0.2.0-preview
Zend Framework=1.9.4
Zend Framework=1.6.0-rc1
Zend Framework=1.8.4
Zend Framework=0.7.0-preview
Zend Framework=1.0.3
Zend Framework=1.5.0-preview
Event History
Dec 24, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4417?
CVE-2009-4417 is classified as having high severity due to its ability to enable attackers to send arbitrary emails.
2
How do I fix CVE-2009-4417?
To mitigate CVE-2009-4417, you should upgrade to a patched version of the Zend Framework that corrects the vulnerability.
3
What versions of Zend Framework are affected by CVE-2009-4417?
CVE-2009-4417 affects multiple versions of Zend Framework, including versions 0.9.0-beta to 1.9.6.
4
What type of vulnerability is CVE-2009-4417?
CVE-2009-4417 is an email injection vulnerability that allows attackers to exploit the logging mechanism.
5
Can CVE-2009-4417 be exploited remotely?
Yes, CVE-2009-4417 can be exploited remotely if the application is not properly secured.