MGASA-2016-0156
Dashboard / Vulnerabilities / MGASA-2016-0156
MGASA-2016-0156
Summary: Updated php-ZendFramework packages fix security vulnerability
Details: The php-ZendFramework package has been updated to version 1.12.18 to fix a potential information disclosure and insufficient entropy vulnerability in the word CAPTCHA (ZF2015-09) and several other functions (ZF2016-01).
References: https://advisories.mageia.org/MGASA-2016-0156.html, https://bugs.mageia.org/show_bug.cgi?id=18258, http://framework.zend.com/security/advisory/ZF2015-09, http://framework.zend.com/security/advisory/ZF2016-01, http://framework.zend.com/blog/zend-framework-1-12-17-and-2-4-9-released.html, http://framework.zend.com/blog/zend-framework-1-12-18-released.html
Affected packages
Package
Name: php-ZendFramework
Purl: pkg:rpm/mageia/php-ZendFramework?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
