A vulnerability in Zend Framework could allow a remote attacker to inject SQL commands.
|Package||dev-php/ZendFramework on all architectures|
|Affected versions||< 1.11.6|
|Unaffected versions||>= 1.11.6|
Zend Framework is a high quality and open source framework for developing Web Applications.
Developers using non-ASCII-compatible encodings in conjunction with the MySQL PDO driver of PHP may be vulnerable to SQL injection attacks.
A remote attacker could use specially crafted input to execute arbitrary SQL statements.
There is no known workaround at this time.
All ZendFramework users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-php/ZendFramework-1.11.6"
NOTE: This is a legacy GLSA. Updates for all affected architectures have been available since 2011-06-07. It is likely that your system is already updated to no longer be affected by this issue.
August 04, 2014
August 04, 2014: 1