LWN.net Logo

php-zendframework: multiple vulnerabilities

Package(s):php-zendframework CVE #(s):
Created:October 8, 2012 Updated:October 10, 2012
Description: From the ZendFramework advisories [1], [2]:

[1] The default error handling view script generated using Zend_Tool failed to escape request parameters when run in the "development" configuration environment, providing a potential XSS attack vector.

[2] Developers using non-ASCII-compatible encodings in conjunction with the MySQL PDO driver of PHP may be vulnerable to SQL injection attacks. Developers using ASCII-compatible encodings like UTF8 or latin1 are not affected by this PHP issue.

Alerts:
Mageia MGASA-2012-0285 2012-10-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds