RULE(RULE ID:332782)

Rule General Information
Release Date: 2021-01-22
Rule Name: Zend Framework Remote Code Execution Vulnerability (CVE-2021-3007)
Severity:
CVE ID:
Rule Protection Details
Description: ** DISPUTED ** Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://github.com/Ling-Yizhou/zendframework3-/blob/main/zend%20framework3%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%20rce.md
https://github.com/laminas/laminas-http/commits/2.15.x/src/Response/Stream.php
https://github.com/laminas/laminas-http/pull/48
https://github.com/laminas/laminas-http/releases/tag/2.14.2
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/laminas/laminas-http/commits/2.15.x/src/Response/Stream.php