A vulnerability in Zend Framework could allow a remote attacker to inject SQL commands.
Package | dev-php/ZendFramework on all architectures |
---|---|
Affected versions | < 1.11.6 |
Unaffected versions | >= 1.11.6 |
Zend Framework is a high quality and open source framework for developing Web Applications.
Developers using non-ASCII-compatible encodings in conjunction with the MySQL PDO driver of PHP may be vulnerable to SQL injection attacks.
A remote attacker could use specially crafted input to execute arbitrary SQL statements.
There is no known workaround at this time.
All ZendFramework users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-php/ZendFramework-1.11.6"
NOTE: This is a legacy GLSA. Updates for all affected architectures have been available since 2011-06-07. It is likely that your system is already updated to no longer be affected by this issue.
Release date
August 04, 2014
Latest revision
August 04, 2014: 1
Severity
normal
Exploitable
remote
Bugzilla entries