Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 3265-2] zendframework regression update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 3265-2] zendframework regression update


Chronologisch Thread 
  • From: Alessandro Ghedini <ghedo AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 3265-2] zendframework regression update
  • Date: Sun, 24 May 2015 13:55:24 +0200
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
  • Old-return-path: <alessandro AT ghedini.me>
  • Priority: urgent
  • Resent-date: Sun, 24 May 2015 11:55:45 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <LeebjgNiwME.A.M2D.BxbYVB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3265-2 security AT debian.org
http://www.debian.org/security/ Alessandro Ghedini
May 24, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : zendframework

The update for zendframework issued as DSA-3265-1 introduced a regression
preventing the use of non-string or non-stringable objects as header
values. A fix for this problem is now applied, along with the final patch
for CVE-2015-3154. For reference the original advisory text follows.

Multiple vulnerabilities were discovered in Zend Framework, a PHP
framework. Except for CVE-2015-3154, all these issues were already fixed
in the version initially shipped with Jessie.

CVE-2014-2681

Lukas Reschke reported a lack of protection against XML External
Entity injection attacks in some functions. This fix extends the
incomplete one from CVE-2012-5657.

CVE-2014-2682

Lukas Reschke reported a failure to consider that the
libxml_disable_entity_loader setting is shared among threads in the
PHP-FPM case. This fix extends the incomplete one from
CVE-2012-5657.

CVE-2014-2683

Lukas Reschke reported a lack of protection against XML Entity
Expansion attacks in some functions. This fix extends the incomplete
one from CVE-2012-6532.

CVE-2014-2684

Christian Mainka and Vladislav Mladenov from the Ruhr-University
Bochum reported an error in the consumer's verify method that lead
to acceptance of wrongly sourced tokens.

CVE-2014-2685

Christian Mainka and Vladislav Mladenov from the Ruhr-University
Bochum reported a specification violation in which signing of a
single parameter is incorrectly considered sufficient.

CVE-2014-4914

Cassiano Dal Pizzol discovered that the implementation of the ORDER
BY SQL statement in Zend_Db_Select contains a potential SQL
injection when the query string passed contains parentheses.

CVE-2014-8088

Yury Dyachenko at Positive Research Center identified potential XML
eXternal Entity injection vectors due to insecure usage of PHP's DOM
extension.

CVE-2014-8089

Jonas Sandström discovered an SQL injection vector when manually
quoting value for sqlsrv extension, using null byte.

CVE-2015-3154

Filippo Tessarotto and Maks3w reported potential CRLF injection
attacks in mail and HTTP headers.

For the oldstable distribution (wheezy), this problem has been fixed
in version 1.11.13-1.1+deb7u2.

For the stable distribution (jessie), this problem has been fixed in
version 1.12.9+dfsg-2+deb8u2.

For the testing distribution (stretch), this problem has been fixed
in version 1.12.13+dfsg-1.

For the unstable distribution (sid), this problem has been fixed in
version 1.12.13+dfsg-1.

We recommend that you upgrade your zendframework packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJVYbwoAAoJEK+lG9bN5XPLp2kP/0UYC2HxoJFR0awEmIjsSIlg
FZ12hGDbisof4gOjpI3+3lbXx2VXbG91gx4YRPwJ6bPI+I1D9C8UdW119RwBXWQU
7FWKTUMihB63xlibMGunMZg6hshRrJFgFTrjCHQu+8SdKENLbn28dGUOeLMaZ3OP
99bkuygn1JO9jeOUipOpzfoSI4SROtfr/O3wBFQ+UdDq7I4Le4EUgibEvkorvg4Y
z697e8U6ale5+u0n76Nl6I8x2P3UsqR1OsGzxnu1Yp2rvdATrr+2A9QynLep3ONO
/kJHMtoouD2oiLnmL4kBLkotRZk6+IXSJUm2+q5pv36KEp1Nyt2ELQuvBXHcMXe7
LLhLsbN9ZR2RvHjP5JeKeP5SpO4WyHZtyhrvA+V3UrnXCaELeuxU9NwrdXRA9ddi
A079p/56yZcsVBPq/PpsrmCdyx//tfzx11iW48gbvay9inY7sZ6JBEk1bX8Z3Y/d
VBabBzt0ulT1XS6VOGLV5d8n332oHLoL0iKOKjQAIH3rlNPVaNkaneQwVWMbDWIF
NFfF/TvtiScdOH36xfzBTeo9inU8VIaBA3OxTrtAxz7WbyvMiICgKbLBjuThK/6h
6f8+zxg+tQVKYUHMfXUL7z2EHbsZcDNfClXNBw92DA8ttyRg5vpBDVOIv6m56Pso
FmtdkBeOUSwfOAssckP1
=ga4o
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST AT lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster AT lists.debian.org
Archive: 20150524115535.9D10B291 AT bendel.debian.org">https://lists.debian.org/20150524115535.9D10B291 AT bendel.debian.org




  • [IT-SecNots] [SECURITY] [DSA 3265-2] zendframework regression update, Alessandro Ghedini, 24.05.2015

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang