CVE-2014-8088: Medium severity vmware spring framework vulnerability
Anonymous authentication in ldapbind() function of PHP, using null byte
Other sources
The (1) ZendLdap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8088?
CVE-2014-8088 has a medium severity rating as it allows attackers to bypass authentication in certain versions of Zend Framework.
How do I fix CVE-2014-8088?
To fix CVE-2014-8088, upgrade to Zend Framework version 1.12.9 or 2.2.8 and above.
Which versions are affected by CVE-2014-8088?
CVE-2014-8088 affects Zend Framework versions before 1.12.9 and 2.x versions before 2.2.8 or 2.3.3.
What attacks are possible due to CVE-2014-8088?
Attackers can exploit CVE-2014-8088 to bypass authentication using a password that starts with a null byte.
Is there a workaround for CVE-2014-8088?
There are no specific workarounds for CVE-2014-8088; the recommended action is to update to the patched versions.