Mandriva Linux Security Advisory MDVSA-2014:145
http://www.mandriva.com/en/
______________________________
Package : php-ZendFramework
Date : July 31, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
A vulnerability has been found and corrected in php-ZendFramework:
The implementation of the ORDER BY SQL statement in Zend_Db_Select
of Zend Framework 1 contains a potential SQL injection when the query
string passed contains parentheses (CVE-2014-4914).
The updated packages have been upgraded to the latest ZendFramework
(1.12.7) version which is not vulnerable to this issue.
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://framework.zend.com/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
f9e5804a58b8af73a972bfa0a2da62
1a5d10af134d2b517d3752a8119b23
1d37c1497156c59d7539333b2b413e
99414b75a630264f9dcfe4c8dfa53e
9ac1fb5c76b9f0b71abf1bf90a273e
d25f8e0658bbe3ce7f026d20baeeba
75218f17b04edc9c422aa811723941
9ca8a5d6aa73e77f2e679e5020be0d
46c3592a516b33b3f30fa6603d9085
aecf3e6879dca04b9084660c5f4906
44829853ef1ac199da93b5affaec80
2338a7798d2ce6f72666a1fcedfe9b
914762e556834e2ce9e17d6d10ad81
a8bd5d5bc7c4c8579278e22650a4d3
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą