Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 302-1] zendframework security update

Recommended Posts

Package : zendframework

Version : 1.10.6-1squeeze5

CVE ID : CVE-2015-5161

 

Dawid Golunski discovered that when running under PHP-FPM in a threaded

environment, Zend Framework, a PHP framework, did not properly handle XML data

in multibyte encoding. This could be used by remote attackers to perform an XML

External Entity attack via crafted XML data.

 

For Debian 6 “Squeezeâ€Â, this issue has been fixed in zendframework

version 1.10.6-1squeeze5.

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×