PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-4861 Fedoraproject CVE debrief

Zend Framework’s Zend_Db_Select order() and group() methods were vulnerable to SQL injection when SQL comments were not removed before validation. NVD rates the issue critical, and the affected range is listed as Zend Framework before 1.12.20.

Vendor
Fedoraproject
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-17
Original CVE updated
2026-05-13
Advisory published
2017-02-17
Advisory updated
2026-05-13

Who should care

Teams running Zend Framework applications, especially code that uses Zend_Db_Select::order() or ::group(), and operators of packaged deployments that may include affected Zend Framework builds.

Technical summary

The issue is classified as CWE-89 SQL injection. According to the NVD record, Zend_Db_Select’s order and group methods failed to strip SQL comments before validation, which could let attacker-controlled input alter the resulting SQL. NVD assigns CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerable Zend Framework range is before 1.12.20, and the NVD CPE data also marks Fedora 23, 24, and 25 as vulnerable.

Defensive priority

Critical — patch immediately.

Recommended defensive actions

  • Upgrade Zend Framework to 1.12.20 or later everywhere it is used.
  • Audit application code for user-controlled inputs passed into Zend_Db_Select::order() and ::group().
  • Confirm downstream packages and vendor builds are updated, including any Fedora package references tied to this CVE.
  • Add regression tests for query-building paths that use SQL fragments, comments, or other nontrivial input.
  • If patching cannot happen immediately, reduce exposure of affected endpoints and monitor for unusual SQL errors or suspicious query patterns.

Evidence notes

This debrief is based on the official CVE and NVD records plus the linked Zend and JVN advisories. The NVD record identifies the weakness as CWE-89 and rates it CVSS 3.0 9.8. The source data lists Zend Framework versions before 1.12.20 as vulnerable and includes Fedora 23/24/25 CPE entries marked vulnerable. No exploit code or reproduction details are included here.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-4861 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-4861

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-4861 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4861

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://framework.zend.com/security/advisory/ZF2016-03

    [email protected] - Exploit, Technical Description, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://lists.debian.org/debian-lts-announce/2018/06/msg00012.html

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2JUKFTI6ABK7ZN7IEAGPCLAHCFANMID2/

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N27AV6AL6B4KGEP3VIMIHQ5LFAKF5FTU/

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UR5HXNGIUSSIZKMSZYMPBEPZEZTYFTIT/

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.