U radu programskog paketa php-doctrine-Doctrine, na operacijskom sustavu Fedora 14, uočena je i ispravljena nova sigurnosna ranjivost. Riječ je o alatu za objektno-relacijsko mapiranje namijenjenom PHP-u. Ranjivost je posljedica pogreške u funkciji "::modifyLimitQuery()" vezane uz obradu ulaznih podataka. Zlonamjerni korisnici mogu ju iskoristiti za napade umetanjem SQL naredbi. Objavljeni su nadograđeni paketi koji ispravljaju opisanu ranjivost te se svim korisnicima savjetuje njihova primjena.
Fedora Update Notification
2011-03-25 19:03:35
Name : php-doctrine-Doctrine
Product : Fedora 14
Version : 1.2.4
Release : 1.fc14
URL : http://www.doctrine-project.org/
Summary : PHP Object Relational Mapper
Description :
Doctrine is an object relational mapper (ORM) for PHP 5.2.3+ that sits on top
of a powerful database abstraction layer (DBAL). One of its key features is
option to write database queries in a proprietary object oriented SQL dialect
called Doctrine Query Language (DQL), inspired by Hibernates HQL. This
developers with a powerful alternative to SQL that maintains flexibility
without requiring unnecessary code duplication.
Update Information:
upstream 1.2.4 security update, see:
* Thu Mar 24 2011 Christof Damian <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.2.4-1
- upstream 1.2.4 security update
* Wed Feb 9 2011 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- 1.2.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
[ 1 ] Bug #689396 - php-doctrine-Doctrine-1.2.4 is available
This update can be installed with the "yum" update program. Use
su -c 'yum update php-doctrine-Doctrine' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke