MGASA-2015-0391
Dashboard / Vulnerabilities / MGASA-2015-0391
Summary: Updated php-ZendFramework/php-ZendFramework2 packages fixe security vulnerabilities
Details: Zend Framework contained several instances where it was using incorrect permissions masks, which could lead to local privilege escalation issues (CVE-2015-5723). The PDO adapters of Zend Framework 1 do not filter null bytes values in SQL statements. A PDO adapter can treat null bytes in a query as a string terminator, allowing an attacker to add arbitrary SQL following a null byte, and thus create a SQL injection (ZF2015-08). Note that the ZF2015-08 issue did not affect Zend Framework 2.
References: https://advisories.mageia.org/MGASA-2015-0391.html, https://bugs.mageia.org/show_bug.cgi?id=16828, http://framework.zend.com/security/advisory/ZF2015-07, http://framework.zend.com/security/advisory/ZF2015-08, https://lists.fedoraproject.org/pipermail/package-announce/2015-September/167698.html
Affected packages
Package
Name: php-ZendFramework
Purl: pkg:rpm/mageia/php-ZendFramework?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
