ALAS-2014-460 ---- php-ZendFrameworkID: oval:org.secpod.oval:def:1600003 | Date: (C)2016-01-19 (M)2022-10-10 |
Class: PATCH | Family: unix |
The Zend_Ldap class in Zend before 1.12.9 and Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind. The 1.12.9, 2.2.8, and 2.3.3 releases of the Zend Framework fix an SQL injection issue when using the sqlsrv PHP extension. Full details are available in the upstream advisory
Platform: |
Amazon Linux AMI |
Product: |
php-ZendFramework |