CVE-2024-9129: Format String Injection in Zend Server
Published Oct 22, 2024
·Updated
In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered.
Reported by Dylan Marino
Affected Software
1 affected component
Zend Server<9.2
Event History
Oct 22, 2024
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9129?
CVE-2024-9129 has a high severity rating due to the potential for format string injection vulnerabilities.
2
How do I fix CVE-2024-9129?
To fix CVE-2024-9129, upgrade to Zend Server version 9.2 or later.
3
What versions of Zend Server are affected by CVE-2024-9129?
CVE-2024-9129 affects all versions of Zend Server up to and including 8.5.
4
What is a format string injection vulnerability as seen in CVE-2024-9129?
A format string injection vulnerability allows an attacker to manipulate the input to a function that interprets format strings, potentially leading to arbitrary code execution.
5
Who reported CVE-2024-9129?
CVE-2024-9129 was reported by Dylan Marino.