MEDIUM
The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."
Published Dec 24, 2009
5.0
MEDIUMCVSS 2.0
EPSS 0.86%
Description
The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."
Affected products
No data.
OR
- ≤ 1.9.6
- 0.1.3
- 0.1.4
- 0.1.5
- 0.2.0
- 0.6.0
- 0.7.0
- 0.8.0
- 0.9.0
- 0.9.1
- 0.9.2
- 0.9.3
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.1
- 1.6.2
- 1.7.0
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.4
- 1.7.5
- 1.7.6
- 1.7.7
- 1.7.8
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.9
- 1.9.0
- 1.9.0
- 1.9.0
- 1.9.0
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
- 1.9.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- http://www.sektioneins.de/en/advisories/advisory-032009-piwik-cookie-unserialize-vulnerability/ x_refsource_MISCExploit
- http://www.suspekt.org/2009/12/09/advisory-032009-piwik-cookie-unserialize-vulnerability/ x_refsource_MISCExploit
| Link | Providers | Tags |
|---|---|---|
| http://www.sektioneins.de/en/advisories/advisory-032009-piwik-cookie-unserialize-vulnerability/ | x_refsource_MISCExploit | |
| http://www.suspekt.org/2009/12/09/advisory-032009-piwik-cookie-unserialize-vulnerability/ | x_refsource_MISCExploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2009
Updated Sep 16, 2024
Reserved Dec 24, 2009
Link CVE-2009-4417
CISA Vulnrichment
Updated n/a