CVE-2012-2682
published 2014-07-19CVE-2012-2682: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.79%
76.1th percentile
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_mrg | — | — |
| zendframework | zendframework1 | >= 0 < 1.12.4 | 1.12.4 |
| zendframework | zendopenid | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendrest | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendservice-amazon | >= 0 < 2.0.3 | 2.0.3 |
| zendframework | zendservice-api | >= 0 < 1.0.0 | 1.0.0 |
| zendframework | zendservice-audioscrobbler | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendservice-nirvanix | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendservice-slideshare | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendservice-technorati | >= 0 < 2.0.2 | 2.0.2 |
| zendframework | zendservice-windowsazure | >= 0 < 2.0.2 | 2.0.2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Several Zend Products Vulnerable to XXE and XEE attacks
ghsa·2022-05-14·CVSS 5.0
CVE-2014-2682 [MEDIUM] CWE-611 Several Zend Products Vulnerable to XXE and XEE attacks
Several Zend Products Vulnerable to XXE and XEE attacks
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity (XXE) attacks via an XML external entity declaration in conjunction with an entity reference. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.
GHSA
GHSA-24fh-vxfp-5g6v: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2
ghsa_unreviewed·2022-05-13
CVE-2012-2682 [MEDIUM] CWE-20 GHSA-24fh-vxfp-5g6v: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.
Red Hat
cumin: DoS via displayed link names containing non-ASCII characters
vendor_redhat·2014-07-09·CVSS 5.0
CVE-2012-2682 [MEDIUM] cumin: DoS via displayed link names containing non-ASCII characters
cumin: DoS via displayed link names containing non-ASCII characters
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.
It was found that if Cumin were asked to display a link name containing non-ASCII characters, the request would terminate with an error. If data containing non-ASCII characters were added to the database (such as via Cumin or Wallaby), requests to load said data would terminate and the requested page would not be displayed until an administrator cleans the database.
Package: cumin (Red Hat Enterprise MRG 1) - Will not fix
No detection rules found.
No public exploits indexed.
2014-07-19
Published