|
|
Log in / Subscribe / Register

zendframework: SQL injection

Package(s):zendframework CVE #(s):CVE-2016-4861
Created:October 6, 2016 Updated:October 24, 2016
Description: From the Debian-LTS advisory:

CVE-2016-4861: The implementation of ORDER BY and GROUP BY in Zend_Db_Select remained prone to SQL injection when a combination of SQL expressions and comments were used. This security patch provides a comprehensive solution that identifies and removes comments prior to checking validity of the statement to ensure no SQLi vectors occur.

Alerts:
Mageia MGASA-2016-0352 php-ZendFramework 2016-10-21
Fedora FEDORA-2016-77e5105570 php-ZendFramework 2016-10-09
Fedora FEDORA-2016-7f193a0c59 php-ZendFramework 2016-10-09
Debian-LTS DLA-646-1 zendframework 2016-10-05

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds