From Mageia wiki
Jump to: navigation, search

MGASA-2012-0285

Date: October 6th, 2012
Affected releases: 1


Description:
This security update for php-ZendFramework corrects:

ZF2011-01: Potential XSS in Development Environment Error View Script
ZF2011-02: Potential SQL Injection Vector When Using PDO_MySql


Updated Packages:
php-ZendFramework-1.11.11-1.mga1
php-ZendFramework-demos-1.11.11-1.mga1
php-ZendFramework-tests-1.11.11-1.mga1
php-ZendFramework-extras-1.11.11-1.mga1
php-ZendFramework-Cache-Backend-Apc-1.11.11-1.mga1
php-ZendFramework-Cache-Backend-Memcached-1.11.11-1.mga1
php-ZendFramework-Captcha-1.11.11-1.mga1
php-ZendFramework-Dojo-1.11.11-1.mga1
php-ZendFramework-Feed-1.11.11-1.mga1
php-ZendFramework-Gdata-1.11.11-1.mga1
php-ZendFramework-Pdf-1.11.11-1.mga1
php-ZendFramework-Search-Lucene-1.11.11-1.mga1
php-ZendFramework-Services-1.11.11-1.mga1


References:
http://framework.zend.com/security/advisory/ZF2011-01
http://framework.zend.com/security/advisory/ZF2011-02
https://bugs.mageia.org/show_bug.cgi?id=7083