Debian Security Advisory
DSA-2505-1 zendframework -- information disclosure
- Date Reported:
- 29 Jun 2012
- Affected Packages:
- zendframework
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 679215.
In Mitre's CVE dictionary: CVE-2012-3363. - More information:
-
An XML External Entities inclusion vulnerability was discovered in Zend Framework, a PHP library. This vulnerability may allow attackers to access to local files, depending on how the framework is used.
For the stable distribution (squeeze), this problem has been fixed in version 1.10.6-1squeeze1.
For the unstable distribution (sid), this problem has been fixed in version 1.11.12-1.
We recommend that you upgrade your zendframework packages.