{"id":"MGASA-2016-0196","summary":"Updated php-ZendFramework2 packages fix CVE-2015-7503","details":"Updated php-ZendFramework2 packages fix security vulnerability:\n\nZend\\Crypt\\PublicKey\\Rsa\\PublicKey has a call to openssl_public_encrypt() which\nuses PHP's default $padding argument, which specifies OPENSSL_PKCS1_PADDING,\nindicating usage of PKCS1v1.5 padding. This padding has a known vulnerability,\nthe Bleichenbacher's chosen-ciphertext attack, which can be used to decrypt\narbitrary ciphertexts (CVE-2015-7503).\n","modified":"2026-04-16T06:25:43.120428303Z","published":"2016-05-21T22:11:24Z","upstream":["CVE-2015-7503"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0196.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18259"},{"type":"ADVISORY","url":"http://framework.zend.com/security/advisory/ZF2015-10"}],"affected":[{"package":{"name":"php-ZendFramework2","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/php-ZendFramework2?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.9-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0196.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}