[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-460 ---- php-ZendFramework

ID: oval:org.secpod.oval:def:1600003Date: (C)2016-01-19   (M)2022-10-10
Class: PATCHFamily: unix




The Zend_Ldap class in Zend before 1.12.9 and Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind. The 1.12.9, 2.2.8, and 2.3.3 releases of the Zend Framework fix an SQL injection issue when using the sqlsrv PHP extension. Full details are available in the upstream advisory

Platform:
Amazon Linux AMI
Product:
php-ZendFramework
Reference:
ALAS-2014-460
CVE-2014-8088
CVE-2014-8089
CVE    2
CVE-2014-8088
CVE-2014-8089
CPE    2
cpe:/o:amazon:linux
cpe:/a:zend:php-zendframework

© SecPod Technologies