zend-framework 1.5.3-0ubuntu2.1 source package in Ubuntu
Changelog
zend-framework (1.5.3-0ubuntu2.1) intrepid-security; urgency=low * SECURITY UPDATE: (LP: #345682) Announcement: http://www.nabble.com/SECURITY-ADVISORY-tp22609193p22609193.html From Zend PHP FW Mailing List: The Zend Framework team was recently notified of an XSS attack vector in its Zend_Filter_StripTags class. Zend_Filter_StripTags offers the ability to strip HTML tags from text, but also to selectively choose which tags and specific attributes of those tags to keep. The XSS attack vector was due to a bug in matching HTML tag attributes to retain. If whitespace was introduced surrounding the attribute assignment operator or the value included newline characters, the attribute would always be included in the final output- even if it was not marked to retain. A security fix has been created and released with Zend Framework 1.7.7. Additionally, the fix has been back-ported to the 1.6, 1.5, and 1.0 release branches. * debian/patches/zf_Zend_Filter_security_fix.patch: Fixes security issue according to http://framework.zend.com/svn/framework/standard/branches/release-1.7/library/Zend/Filter/StripTags.php -- Stephan Hermann <email address hidden> Thu, 14 May 2009 12:31:49 +0000
Upload details
- Uploaded by:
- Stephan RĂ¼gamer
- Sponsored by:
- Kees Cook
- Uploaded to:
- Intrepid
- Original maintainer:
- MOTU
- Architectures:
- all
- Section:
- web
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
zend-framework_1.5.3.orig.tar.gz | 4.1 MiB | 6135ced4bc0d3b7b42697a79cbd7681f4e03dfbe77d4824315f25264c9068e9d |
zend-framework_1.5.3-0ubuntu2.1.diff.gz | 6.5 KiB | 8e25ecc1d53986fc6665d684645940f3af4f9bd5c5ec5c163f5fabd3ca4ad12c |
zend-framework_1.5.3-0ubuntu2.1.dsc | 1.2 KiB | d38901f9d8261062bedc6504f77d94c92f07c5d187aa4ef10d37ebb379fdb966 |
Available diffs
Binary packages built by this source
- libzend-framework-php: No summary available for libzend-framework-php in ubuntu intrepid.
No description available for libzend-
framework- php in ubuntu intrepid.
- zend-framework: No summary available for zend-framework in ubuntu intrepid.
No description available for zend-framework in ubuntu intrepid.