Advisories ยป MGASA-2014-0311

Updated php-ZendFramework packages fix security vulnerability

Publication date: 05 Aug 2014
Modification date: 05 Aug 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-4914

Description

The implementation of the ORDER BY SQL statement in Zend_Db_Select of Zend
Framework 1 contains a potential SQL injection when the query string passed
contains parentheses (CVE-2014-4914).
                

References

SRPMS

3/core

4/core