zend-framework 1.5.3-0ubuntu2.1 source package in Ubuntu

Changelog

zend-framework (1.5.3-0ubuntu2.1) intrepid-security; urgency=low

  * SECURITY UPDATE: (LP: #345682)
    Announcement: http://www.nabble.com/SECURITY-ADVISORY-tp22609193p22609193.html
    From Zend PHP FW Mailing List:
    The Zend Framework team was recently notified of an XSS attack vector in its Zend_Filter_StripTags class.
    Zend_Filter_StripTags offers the ability to strip HTML tags from text, but also to selectively choose
    which tags and specific attributes of those tags to keep.
    The XSS attack vector was due to a bug in matching HTML tag attributes to retain.
    If whitespace was introduced surrounding the attribute assignment operator or the value included newline characters,
    the attribute would always be included in the final output- even if it was not marked to retain.
    A security fix has been created and released with Zend Framework 1.7.7.
    Additionally, the fix has been back-ported to the 1.6, 1.5, and 1.0 release branches.
  * debian/patches/zf_Zend_Filter_security_fix.patch:
    Fixes security issue according to
    http://framework.zend.com/svn/framework/standard/branches/release-1.7/library/Zend/Filter/StripTags.php

 -- Stephan Hermann <email address hidden>   Thu, 14 May 2009 12:31:49 +0000

Upload details

Uploaded by:
Stephan RĂ¼gamer
Sponsored by:
Kees Cook
Uploaded to:
Intrepid
Original maintainer:
MOTU
Architectures:
all
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Intrepid: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
zend-framework_1.5.3.orig.tar.gz 4.1 MiB 6135ced4bc0d3b7b42697a79cbd7681f4e03dfbe77d4824315f25264c9068e9d
zend-framework_1.5.3-0ubuntu2.1.diff.gz 6.5 KiB 8e25ecc1d53986fc6665d684645940f3af4f9bd5c5ec5c163f5fabd3ca4ad12c
zend-framework_1.5.3-0ubuntu2.1.dsc 1.2 KiB d38901f9d8261062bedc6504f77d94c92f07c5d187aa4ef10d37ebb379fdb966

View changes file

Binary packages built by this source

libzend-framework-php: No summary available for libzend-framework-php in ubuntu intrepid.

No description available for libzend-framework-php in ubuntu intrepid.

zend-framework: No summary available for zend-framework in ubuntu intrepid.

No description available for zend-framework in ubuntu intrepid.