zend-framework 1.5.1-0ubuntu1.1 source package in Ubuntu

Changelog

zend-framework (1.5.1-0ubuntu1.1) hardy-security; urgency=low

  * SECURITY UPDATE: (LP: #345682)
    Announcement: http://www.nabble.com/SECURITY-ADVISORY-tp22609193p22609193.html
    From Zend PHP FW Mailing List:
    The Zend Framework team was recently notified of an XSS attack vector in its Zend_Filter_StripTags class.
    Zend_Filter_StripTags offers the ability to strip HTML tags from text, but also to selectively choose
    which tags and specific attributes of those tags to keep.
    The XSS attack vector was due to a bug in matching HTML tag attributes to retain.
    If whitespace was introduced surrounding the attribute assignment operator or the value included newline characters,
    the attribute would always be included in the final output- even if it was not marked to retain.
    A security fix has been created and released with Zend Framework 1.7.7.
    Additionally, the fix has been back-ported to the 1.6, 1.5, and 1.0 release branches.
  * debian/patches/zf_Zend_Filter_security_fix.patch:
    Fixes security issue according to
    http://framework.zend.com/svn/framework/standard/branches/release-1.7/library/Zend/Filter/StripTags.php
  * debian/control: added quilt as build dependency
  * debian/rules: include quilt.mk and call patch/unpatch targets

 -- Stephan Hermann <email address hidden>   Thu, 14 May 2009 12:39:55 +0000

Upload details

Uploaded by:
Stephan RĂ¼gamer
Sponsored by:
Kees Cook
Uploaded to:
Hardy
Original maintainer:
MOTU
Architectures:
all
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Hardy: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
zend-framework_1.5.1.orig.tar.gz 4.1 MiB 63e298275418b61ae3d7edc4b2d181d221977642edb5808b48f6001609f7a030
zend-framework_1.5.1-0ubuntu1.1.diff.gz 5.0 KiB a5a992a2e07907ae080fbc01fb4f20bf56fe1cb3d823853cdd2f12481bcee032
zend-framework_1.5.1-0ubuntu1.1.dsc 756 bytes ee0cc1cfea5ed841338a616bae068dc9d9e43f721f0312d71a94685e902761cb

View changes file

Binary packages built by this source

libzend-framework-php: No summary available for libzend-framework-php in ubuntu hardy.

No description available for libzend-framework-php in ubuntu hardy.

zend-framework: No summary available for zend-framework in ubuntu hardy.

No description available for zend-framework in ubuntu hardy.