zend-framework 1.7.5-0ubuntu2.2 source package in Ubuntu

Changelog

zend-framework (1.7.5-0ubuntu2.2) jaunty-security; urgency=low

  * The security update fixes the following security issues: (LP: #506304)
    + ZF2010-03: Potential XSS vector in Zend_Filter_StripTags when comments allowed
      Zend_Filter_StripTags contained an optional setting to allow whitelisting
      HTML comments in filtered text. Microsoft Internet Explorer and several other
      browsers allow developers to create conditional functionality via HTML comments,
      including execution of script events and rendering of additional commented markup.
      By allowing whitelisting of HTML comments, a malicious user could potentially
      include XSS exploits within HTML comments that would then be rendered in the final output.
      http://framework.zend.com/security/advisory/ZF2010-03
    + ZF2010-06: Potential XSS or HTML Injection vector in Zend_Json
      Zend_Json_Encoder was not taking into account the solidus character ("/") during encoding,
      leading to incompatibilities with the JSON specification, and opening the potential for XSS
      or HTML injection attacks when returning HTML within a JSON string.
    + ZF2010-02: Potential XSS vector in Zend_Dojo_View_Helper_Editor
      Zend_Dojo_View_Helper_Editor was incorrectly decorating a TEXTAREA instead of a DIV.
      The Dojo team has reported that this has security implications as the rich
      text editor they use is unable to escape content for a TEXTAREA.
  * debian/patches/99_ZF2010-03_Zend_Filter_Striptags.patch:
    + Patch was found at: http://framework.zend.com/issues/browse/ZF-8743
  * debian/patches/99_ZF2010-06_Zend_Json.patch
    + Patch was found: http://framework.zend.com/issues/browse/ZF-8663
  * debian/patches/99_ZF2010-02_Zend_Dojo.patch:
    + Patch was found: http://framework.zend.com/issues/browse/ZF-6753
 -- Stephan Hermann <email address hidden>   Tue, 12 Jan 2010 11:14:21 +0000

Upload details

Uploaded by:
Stephan RĂ¼gamer
Sponsored by:
Marc Deslauriers
Uploaded to:
Jaunty
Original maintainer:
MOTU
Architectures:
all
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Jaunty: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
zend-framework_1.7.5.orig.tar.gz 20.3 MiB 16559635e591af04f01ea66a2ad98dbdd39c75a890f4301611517b799916c62f
zend-framework_1.7.5-0ubuntu2.2.diff.gz 37.9 KiB dcf4608f2dcdf1247aa0dd90616383a1771f93c099880bea0c13aa14617ad5e2
zend-framework_1.7.5-0ubuntu2.2.dsc 1.1 KiB d38db90f4f359fc8b3eaf7e85b2c403efb5b4770e035e93212ddae57514b0830

View changes file

Binary packages built by this source

libzend-framework-php: No summary available for libzend-framework-php in ubuntu jaunty.

No description available for libzend-framework-php in ubuntu jaunty.

zend-framework: No summary available for zend-framework in ubuntu jaunty.

No description available for zend-framework in ubuntu jaunty.