CVE Vulnerabilities

CVE-2009-4417

Published: Dec 24, 2009 | Modified: Dec 28, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to events not yet mailed.

Affected Software

Name Vendor Start Version End Version
Framework Zend * 1.9.6 (including)
Framework Zend 0.1.3-preview (including) 0.1.3-preview (including)
Framework Zend 0.1.4-preview (including) 0.1.4-preview (including)
Framework Zend 0.1.5-preview (including) 0.1.5-preview (including)
Framework Zend 0.2.0-preview (including) 0.2.0-preview (including)
Framework Zend 0.6.0-preview (including) 0.6.0-preview (including)
Framework Zend 0.7.0-preview (including) 0.7.0-preview (including)
Framework Zend 0.8.0-preview (including) 0.8.0-preview (including)
Framework Zend 0.9.0-beta (including) 0.9.0-beta (including)
Framework Zend 0.9.1-beta (including) 0.9.1-beta (including)
Framework Zend 0.9.2-beta (including) 0.9.2-beta (including)
Framework Zend 0.9.3-beta (including) 0.9.3-beta (including)
Framework Zend 1.0.0 (including) 1.0.0 (including)
Framework Zend 1.0.0-rc1 (including) 1.0.0-rc1 (including)
Framework Zend 1.0.0-rc2 (including) 1.0.0-rc2 (including)
Framework Zend 1.0.0-rc3 (including) 1.0.0-rc3 (including)
Framework Zend 1.0.1 (including) 1.0.1 (including)
Framework Zend 1.0.2 (including) 1.0.2 (including)
Framework Zend 1.0.3 (including) 1.0.3 (including)
Framework Zend 1.0.4 (including) 1.0.4 (including)
Framework Zend 1.5.0 (including) 1.5.0 (including)
Framework Zend 1.5.0-preview (including) 1.5.0-preview (including)
Framework Zend 1.5.0-rc1 (including) 1.5.0-rc1 (including)
Framework Zend 1.5.0-rc2 (including) 1.5.0-rc2 (including)
Framework Zend 1.5.0-rc3 (including) 1.5.0-rc3 (including)
Framework Zend 1.5.1 (including) 1.5.1 (including)
Framework Zend 1.5.2 (including) 1.5.2 (including)
Framework Zend 1.5.3 (including) 1.5.3 (including)
Framework Zend 1.6.0 (including) 1.6.0 (including)
Framework Zend 1.6.0-rc1 (including) 1.6.0-rc1 (including)
Framework Zend 1.6.0-rc2 (including) 1.6.0-rc2 (including)
Framework Zend 1.6.0-rc3 (including) 1.6.0-rc3 (including)
Framework Zend 1.6.1 (including) 1.6.1 (including)
Framework Zend 1.6.2 (including) 1.6.2 (including)
Framework Zend 1.7.0 (including) 1.7.0 (including)
Framework Zend 1.7.0-preview (including) 1.7.0-preview (including)
Framework Zend 1.7.1 (including) 1.7.1 (including)
Framework Zend 1.7.2 (including) 1.7.2 (including)
Framework Zend 1.7.3 (including) 1.7.3 (including)
Framework Zend 1.7.4 (including) 1.7.4 (including)
Framework Zend 1.7.5 (including) 1.7.5 (including)
Framework Zend 1.7.6 (including) 1.7.6 (including)
Framework Zend 1.7.7 (including) 1.7.7 (including)
Framework Zend 1.7.8 (including) 1.7.8 (including)
Framework Zend 1.8.0 (including) 1.8.0 (including)
Framework Zend 1.8.0-alpha_1 (including) 1.8.0-alpha_1 (including)
Framework Zend 1.8.0-beta_1 (including) 1.8.0-beta_1 (including)
Framework Zend 1.8.1 (including) 1.8.1 (including)
Framework Zend 1.8.2 (including) 1.8.2 (including)
Framework Zend 1.8.3 (including) 1.8.3 (including)
Framework Zend 1.8.4 (including) 1.8.4 (including)
Framework Zend 1.9 (including) 1.9 (including)
Framework Zend 1.9.0 (including) 1.9.0 (including)
Framework Zend 1.9.0-alpha_1 (including) 1.9.0-alpha_1 (including)
Framework Zend 1.9.0-beta_1 (including) 1.9.0-beta_1 (including)
Framework Zend 1.9.0-rc1 (including) 1.9.0-rc1 (including)
Framework Zend 1.9.1 (including) 1.9.1 (including)
Framework Zend 1.9.2 (including) 1.9.2 (including)
Framework Zend 1.9.3 (including) 1.9.3 (including)
Framework Zend 1.9.4 (including) 1.9.4 (including)
Framework Zend 1.9.5 (including) 1.9.5 (including)

References