|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2015-3880 (php-ZendFramework2)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 20 Update: php-ZendFramework2-2.3.7-1.fc20
Date:  Mon, 23 Mar 2015 07:11:56 +0000
Message-ID:  <20150323071156.CBA4A6087A97@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-3880 2015-03-14 05:08:02 -------------------------------------------------------------------------------- Name : php-ZendFramework2 Product : Fedora 20 Version : 2.3.7 Release : 1.fc20 URL : http://framework.zend.com Summary : Zend Framework 2 Description : Zend Framework 2 is an open source framework for developing web applications and services using PHP 5.3+. Zend Framework 2 uses 100% object-oriented code and utilizes most of the new features of PHP 5.3, namely namespaces, late static binding, lambda functions and closures. Zend Framework 2 evolved from Zend Framework 1, a successful PHP framework with over 15 million downloads. Note: This meta package installs all base Zend Framework component packages (Authentication, Barcode, Cache, Captcha, Code, Config, Console, Crypt, Db, Debug, Di, Dom, Escaper, EventManager, Feed, File, Filter, Form, Http, I18n, InputFilter, Json, Ldap, Loader, Log, Mail, Math, Memory, Mime, ModuleManager, Mvc, Navigation, Paginator, Permissions-Acl, Permissions-Rbac, ProgressBar, Serializer, Server, ServiceManager, Session, Soap, Stdlib, Tag, Test, Text, Uri, Validator, Version, View, XmlRpc) except the optional Cache-apc and Cache-memcached packages. -------------------------------------------------------------------------------- Update Information: Version **2.3.7** (2015-03-12) * #7255 Revert BC break against AbstractRestfulController Version **2.3.6** (2015-03-12) * ZF2015-03 Zend\Validator\Csrf was incorrectly testing null or improperly formatted token identifiers, allowing them to pass validation. This release provides patches to correct the behavior. If you use the validator, or the corresponding Zend\Form\Element\Csrf, we recommend upgrading immediately. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 13 2015 Remi Collet <remi@fedoraproject.org> - 2.3.7-1 - Update to 2.3.7 * Tue Feb 24 2015 Remi Collet <remi@fedoraproject.org> - 2.3.5-1 - Update to 2.3.5 - add patch for icu 54, FTBFS detected by Koschei * Fri Jan 16 2015 Remi Collet <remi@fedoraproject.org> - 2.3.4-1 - Update to 2.3.4 - drop GLPI patch, fixed upstream - add dependency on ircmaxell/random-lib - apply upstream changes to inter-package dependencies * Fri Oct 17 2014 Shawn Iwinski <shawn.iwinski@gmail.com> - 2.3.3-2 - Drop php-gmp dependency from Math component (BZ #1152440) - Fix tests' autoloader * Fri Oct 10 2014 Remi Collet <remi@fedoraproject.org> - 2.3.3-1 - Update to 2.3.3 - fix SQL injection with SqlSrv ZF2014-05 CVE-2014-8088 #1151276 - fix null byte issue on Ldap connect ZF2014-06 CVE-2014-8089 #1151277 * Wed Aug 20 2014 Remi Collet <remi@fedoraproject.org> - 2.3.2-1 - Update to 2.3.2 - tests from github - run test suite during build * Sun Jul 20 2014 Remi Collet <remi@fedoraproject.org> - 2.3.1-3 - composer dependencies - add missing license * Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.3.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Tue May 20 2014 Shawn Iwinski <shawn.iwinski@gmail.com> - 2.3.1-1 - Updated to 2.3.1 * Sun May 18 2014 Shawn Iwinski <shawn.iwinski@gmail.com> - 2.2.7-1 - Updated to 2.2.7 (security update for ZF2014-03) * Tue Apr 1 2014 Remi Collet <remi@fedoraproject.org> - 2.2.6-1 - Updated to 2.2.6 for CVE-2014-2681 CVE-2014-2682 CVE-2014-2683 CVE-2014-2684 CVE-2014-2685 - new package ZendXml - fix for unversioned doc directory -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update php-ZendFramework2' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds