Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in php-ZendFramework2
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in php-ZendFramework2
ID: FEDORA-2014-4612
Distribution: Fedora
Plattformen: Fedora 20
Datum: Di, 15. April 2014, 06:28
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2681
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2682
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2683
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2684
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2685
Applikationen: Zend Framework

Originalnachricht

Name        : php-ZendFramework2
Product : Fedora 20
Version : 2.2.6
Release : 1.fc20
URL : http://framework.zend.com
Summary : Zend Framework 2
Description :
Zend Framework 2 is an open source framework for developing web applications
and services using PHP 5.3+. Zend Framework 2 uses 100% object-oriented code
and utilizes most of the new features of PHP 5.3, namely namespaces, late
static binding, lambda functions and closures.

Zend Framework 2 evolved from Zend Framework 1, a successful PHP framework
with over 15 million downloads.

Note: This meta package installs all base Zend Framework component packages
(Authentication, Barcode, Cache, Captcha, Code, Config, Console, Crypt, Db,
Debug, Di, Dom, Escaper, EventManager, Feed, File, Filter, Form, Http, I18n,
InputFilter, Json, Ldap, Loader, Log, Mail, Math, Memory, Mime, ModuleManager,
Mvc, Navigation, Paginator, Permissions-Acl, Permissions-Rbac, ProgressBar,
Serializer, Server, ServiceManager, Session, Soap, Stdlib, Tag, Test, Text,
Uri, Validator, Version, View, XmlRpc) except the optional Cache-apc and
Cache-memcached packages.

-------------------------------------------------------------------------------
-
Update Information:

Upstream release notes:
https://github.com/zendframework/zf2/releases/tag/release-2.2.6

-------------------------------------------------------------------------------
-
ChangeLog:

* Tue Apr 1 2014 Remi Collet <remi@fedoraproject.org> 2.2.6-1
- Updated to 2.2.6 for CVE-2014-2681 CVE-2014-2682
CVE-2014-2683 CVE-2014-2684 CVE-2014-2685
- new package ZendXml
- fix for unversioned doc directory
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1081287 - CVE-2014-2681 CVE-2014-2682 CVE-2014-2683
php-ZendFramework: XML eXternal Entity (XXE) and XML Entity Expansion (XEE) flaws fixed in 1.12.4, 2.1.6, and 2.2.6 (ZF2014-01)
https://bugzilla.redhat.com/show_bug.cgi?id=1081287
[ 2 ] Bug #1081288 - CVE-2014-2684 CVE-2014-2685 php-ZendFramework: OpenID
identity provider could be used to spoof other identity providers (ZF2014-02)
https://bugzilla.redhat.com/show_bug.cgi?id=1081288
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update php-ZendFramework2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung