ubuntu · CVE-2016-4861

Quick triage

Priority: medium Published: 2017-02-17 02:59:00 UTC Updated: 2025-08-26 11:54:20 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-4861 medium priority: Ubuntu including 2 source packages (zend-framework, zendframework), 43 status rows across 22 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, wily, xenial, yakkety, zesty): DNE 34, ignored 4, needed 2, not-affected 2, released 1.

Description:

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

cvelogic Threat Intelligence