Objavljena je nova inačica PHP razvojnog okruženja php-ZendFramework, za operacijske sustave Fedora 13 i 14, koja otklanja mogućnost izvođenja napada umetanja proizvoljnog SQL koda.
Paket: | php-ZendFramework 1.x |
Operacijski sustavi: | Fedora 13, Fedora 14 |
Problem: | neodgovarajuća provjera ulaznih podataka, pogreška u programskoj komponenti |
Iskorištavanje: | lokalno |
Posljedica: | pokretanje SQL koda |
Rješenje: | programska zakrpa proizvođača |
Izvorni ID preporuke: | FEDORA-2011-7409 |
Izvor: | Fedora |
Problem: | |
Potencijalnu ranjivost uzrokuje korištenje postavki upravljačkog programa "PDO_MYSQL" koje ne odgovaraju ASCII standardu. |
|
Posljedica: | |
Uočena ranjivost može se iskoristiti za pokretanje napada umetanja proizvoljnog SQL koda. |
|
Rješenje: | |
Svim korisnicima savjetuje se primjena objavljene nadogradnje. |
Izvorni tekst preporuke
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-7388
2011-05-25 01:54:43
--------------------------------------------------------------------------------
Name : php-ZendFramework
Product : Fedora 13
Version : 1.11.6
Release : 1.fc13
URL : http://framework.zend.com/
Summary : Leading open-source PHP framework
Description :
Extending the art & spirit of PHP, Zend Framework is based on simplicity,
object-oriented best practices, corporate friendly licensing, and a rigorously
tested agile codebase. Zend Framework is focused on building more secure,
reliable, and modern Web 2.0 applications & web services, and consuming widely
available APIs from leading vendors like Google, Amazon, Yahoo!, Flickr, as
well as API providers and catalogers like StrikeIron and ProgrammableWeb.
--------------------------------------------------------------------------------
Update Information:
Fixes ZF2011-02: Potential SQL Injection Vector When Using PDO_MySql
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 23 2011 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.6-1
- update to 1.11.6
- fixes ZF2011-02: Potential SQL Injection Vector When Using PDO_MySql
- full changelog http://framework.zend.com/changelog/1.11.6
* Fri Mar 4 2011 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.4-1
- update to 1.11.4
- over 40 bugs were fixed
- full changelog http://framework.zend.com/changelog/1.11.4
* Wed Feb 9 2011 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.3-1
- update to 1.11.3
- full changelog http://framework.zend.com/changelog/1.11.3
* Wed Feb 9 2011 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- 1.11.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Nov 4 2010 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.0-1
- update to 1.11.0
- new component: Cloud
- full changelog http://framework.zend.com/changelog/1.11.0
- release announcement:
http://devzone.zend.com/article/12724-Zend-Framework-1.11.0-FINAL-Released
* Sun Jul 25 2010 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.10.6-1
- update to 1.10.6 containing over 30 bugfixes
* Sat Jun 12 2010 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.10.5-1
- update to 1.10.5 which contains over 60 bugfixes
* Thu May 13 2010 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.10.4-1
- about 180 bugfixes since 1.10.2 (http://framework.zend.com/changelog/1.10.4)
- fixes ZF2010-07: Potential Security Issues in Bundled Dojo Library
* Wed Mar 3 2010 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.10.2-1
- 1.10.2
- over 50 bugfixes since 1.10.1 (which in turn had over 50 bugfixes)
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update php-ZendFramework' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-7409
2011-05-25 01:55:35
--------------------------------------------------------------------------------
Name : php-ZendFramework
Product : Fedora 14
Version : 1.11.6
Release : 1.fc14
URL : http://framework.zend.com/
Summary : Leading open-source PHP framework
Description :
Extending the art & spirit of PHP, Zend Framework is based on simplicity,
object-oriented best practices, corporate friendly licensing, and a rigorously
tested agile codebase. Zend Framework is focused on building more secure,
reliable, and modern Web 2.0 applications & web services, and consuming widely
available APIs from leading vendors like Google, Amazon, Yahoo!, Flickr, as
well as API providers and catalogers like StrikeIron and ProgrammableWeb.
--------------------------------------------------------------------------------
Update Information:
Fixes ZF2011-02: Potential SQL Injection Vector When Using PDO_MySql
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 23 2011 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.6-1
- update to 1.11.6
- fixes ZF2011-02: Potential SQL Injection Vector When Using PDO_MySql
- full changelog http://framework.zend.com/changelog/1.11.6
* Fri Mar 4 2011 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.4-1
- update to 1.11.4
- over 40 bugs were fixed
- full changelog http://framework.zend.com/changelog/1.11.4
* Wed Feb 9 2011 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.3-1
- update to 1.11.3
- full changelog http://framework.zend.com/changelog/1.11.3
* Wed Feb 9 2011 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- 1.11.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Nov 4 2010 Felix Kaechele <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.11.0-1
- update to 1.11.0
- new component: Cloud
- full changelog http://framework.zend.com/changelog/1.11.0
- release announcement:
http://devzone.zend.com/article/12724-Zend-Framework-1.11.0-FINAL-Released
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update php-ZendFramework' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke