PatchSiren cyber security CVE debrief
CVE-2016-4861 Fedoraproject CVE debrief
Zend Framework’s Zend_Db_Select order() and group() methods were vulnerable to SQL injection when SQL comments were not removed before validation. NVD rates the issue critical, and the affected range is listed as Zend Framework before 1.12.20.
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-17
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-17
- Advisory updated
- 2026-05-13
Who should care
Teams running Zend Framework applications, especially code that uses Zend_Db_Select::order() or ::group(), and operators of packaged deployments that may include affected Zend Framework builds.
Technical summary
The issue is classified as CWE-89 SQL injection. According to the NVD record, Zend_Db_Select’s order and group methods failed to strip SQL comments before validation, which could let attacker-controlled input alter the resulting SQL. NVD assigns CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerable Zend Framework range is before 1.12.20, and the NVD CPE data also marks Fedora 23, 24, and 25 as vulnerable.
Defensive priority
Critical — patch immediately.
Recommended defensive actions
- Upgrade Zend Framework to 1.12.20 or later everywhere it is used.
- Audit application code for user-controlled inputs passed into Zend_Db_Select::order() and ::group().
- Confirm downstream packages and vendor builds are updated, including any Fedora package references tied to this CVE.
- Add regression tests for query-building paths that use SQL fragments, comments, or other nontrivial input.
- If patching cannot happen immediately, reduce exposure of affected endpoints and monitor for unusual SQL errors or suspicious query patterns.
Evidence notes
This debrief is based on the official CVE and NVD records plus the linked Zend and JVN advisories. The NVD record identifies the weakness as CWE-89 and rates it CVSS 3.0 9.8. The source data lists Zend Framework versions before 1.12.20 as vulnerable and includes Fedora 23/24/25 CPE entries marked vulnerable. No exploit code or reproduction details are included here.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-4861 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-4861
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-4861 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4861
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://framework.zend.com/security/advisory/ZF2016-03
[email protected] - Exploit, Technical Description, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2018/06/msg00012.html
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2JUKFTI6ABK7ZN7IEAGPCLAHCFANMID2/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N27AV6AL6B4KGEP3VIMIHQ5LFAKF5FTU/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UR5HXNGIUSSIZKMSZYMPBEPZEZTYFTIT/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.