(1) ZendDom, (2) ZendFeed, (3) ZendSoap, and (4) ZendXmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (CPU consumption) via recursive or circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack.
{
"binaries": [
{
"binary_name": "libzend-framework-php",
"binary_version": "1.11.11-0ubuntu3.16.04.1"
},
{
"binary_name": "libzend-framework-zendx-php",
"binary_version": "1.11.11-0ubuntu3.16.04.1"
},
{
"binary_name": "zend-framework",
"binary_version": "1.11.11-0ubuntu3.16.04.1"
},
{
"binary_name": "zend-framework-bin",
"binary_version": "1.11.11-0ubuntu3.16.04.1"
}
]
}