Updated php-ZendFramework packages fix security vulnerability
Publication date: 05 Aug 2014Modification date: 05 Aug 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-4914
Description
The implementation of the ORDER BY SQL statement in Zend_Db_Select of Zend Framework 1 contains a potential SQL injection when the query string passed contains parentheses (CVE-2014-4914).
References
SRPMS
3/core
- php-ZendFramework-1.12.7-1.mga3
4/core
- php-ZendFramework-1.12.7-1.mga4