{"id":"MGASA-2015-0371","summary":"Updated php-ZendFramework packages fix CVE-2015-5161","details":"Updated php-ZendFramework and php-ZendFramework2 packages fix security vulnerability:\n\nDawid Golunski discovered that when running under PHP-FPM in a threaded\nenvironment, Zend Framework, a PHP framework, did not properly handle XML data\nin multibyte encoding. This could be used by remote attackers to perform an\nXML External Entity attack via crafted XML data (CVE-2015-5161).\n","modified":"2026-04-16T06:25:31.683305157Z","published":"2015-09-15T14:55:06Z","upstream":["CVE-2015-5161"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0371.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=16624"},{"type":"WEB","url":"http://framework.zend.com/blog/zend-framework-1-12-14-2-4-6-and-2-5-2-released.html"},{"type":"WEB","url":"http://framework.zend.com/blog/zend-framework-1-12-15-and-2-4-7-released.html"},{"type":"ADVISORY","url":"http://framework.zend.com/security/advisory/ZF2015-06"},{"type":"WEB","url":"https://www.debian.org/security/2015/dsa-3340"}],"affected":[{"package":{"name":"php-ZendFramework","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/php-ZendFramework?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.15-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0371.json"}},{"package":{"name":"php-ZendFramework2","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/php-ZendFramework2?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.7-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0371.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}