Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 09 Jul 2014 15:33:18 +1000
From: Murray McAllister <>
        Kurt Seifried <>
Subject: Re: Zend Framework CVEs

On 07/09/2014 08:52 AM, Kurt Seifried wrote:
> Hash: SHA1
> As I understand Zend it's a BSD style license, so Open Source, so
> posting here, CC'ing upstream and Mitre. Can we please get CVE's for:
> ZF2014-04: Potential SQL injection in the ORDER implementation of
> Zend_Db_Select
> ZF2014-03: Potential XSS vector in multiple view helpers
> ZF2014-02: Potential security issue in login mechanism of ZendOpenId
> and Zend_OpenId consumer
> ZF2014-01: Potential XXE/XEE attacks using PHP functions:
> simplexml_load_*, DOMDocument::loadXML, and xml_parse

Good morning,

For the ZF2014-01 and ZF2014-02 assignments, refer to


Murray McAllister / Red Hat Product Security

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.