MGASA-2016-0196
Dashboard / Vulnerabilities / MGASA-2016-0196
Summary: Updated php-ZendFramework2 packages fix CVE-2015-7503
Details: Updated php-ZendFramework2 packages fix security vulnerability: Zend\Crypt\PublicKey\Rsa\PublicKey has a call to openssl_public_encrypt() which uses PHP's default $padding argument, which specifies OPENSSL_PKCS1_PADDING, indicating usage of PKCS1v1.5 padding. This padding has a known vulnerability, the Bleichenbacher's chosen-ciphertext attack, which can be used to decrypt arbitrary ciphertexts (CVE-2015-7503).
References: https://advisories.mageia.org/MGASA-2016-0196.html, https://bugs.mageia.org/show_bug.cgi?id=18259, http://framework.zend.com/security/advisory/ZF2015-10
Affected packages
Package
Name: php-ZendFramework2
Purl: pkg:rpm/mageia/php-ZendFramework2?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
