Bug 203462 - www/zend-framework1: security/vuxml: update to 1.12.16 (fixed ZF2015-08 SQL injection advisory)
Summary: www/zend-framework1: security/vuxml: update to 1.12.16 (fixed ZF2015-08 SQL i...
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: William Grzybowski
URL: http://framework.zend.com/security/ad...
Keywords: needs-patch, security
Depends on:
Blocks:
 
Reported: 2015-10-01 02:17 UTC by Jason Unovitch
Modified: 2016-01-03 02:41 UTC (History)
2 users (show)

See Also:
junovitch: merge-quarterly?


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jason Unovitch freebsd_committer freebsd_triage 2015-10-01 02:17:51 UTC
Security Advisory
ZF2015-08: Potential SQL injection vector using null byte for PDO (MsSql, SQLite)

Full Text:
http://framework.zend.com/security/advisory/ZF2015-08
Comment 1 Jason Unovitch freebsd_committer freebsd_triage 2015-10-01 02:18:22 UTC
Also relevant:
http://www.openwall.com/lists/oss-security/2015/09/30/6
Comment 2 commit-hook freebsd_committer freebsd_triage 2015-10-06 15:03:03 UTC
A commit references this bug:

Author: wg
Date: Tue Oct  6 15:02:39 UTC 2015
New revision: 398701
URL: https://svnweb.freebsd.org/changeset/ports/398701

Log:
  security/vuxml: Document Zend Framework 1 vulnerability

  PR:		203462
  Security:	d3324fdb-6bf0-11e5-bc5e-00505699053e
  Security:	CVE-2014-8089

Changes:
  head/security/vuxml/vuln.xml
Comment 3 commit-hook freebsd_committer freebsd_triage 2015-10-06 15:04:05 UTC
A commit references this bug:

Author: wg
Date: Tue Oct  6 15:03:35 UTC 2015
New revision: 398702
URL: https://svnweb.freebsd.org/changeset/ports/398702

Log:
  www/zend-framework1: update to 1.12.16

  PR:		203462
  Security:	d3324fdb-6bf0-11e5-bc5e-00505699053e

Changes:
  head/www/zend-framework1/Makefile
  head/www/zend-framework1/distinfo
  head/www/zend-framework1/pkg-plist
Comment 4 Jason Unovitch freebsd_committer freebsd_triage 2015-10-06 23:44:04 UTC
Add merge-quarterly?

Can you ask to MFH this as it was a security update?
Comment 5 commit-hook freebsd_committer freebsd_triage 2015-10-12 14:20:07 UTC
A commit references this bug:

Author: junovitch
Date: Mon Oct 12 14:19:26 UTC 2015
New revision: 399132
URL: https://svnweb.freebsd.org/changeset/ports/399132

Log:
  Add CVE assignment to r398701 Zend Framework 1 entry

  PR:		203462
  Security:	CVE-2015-7695
  Security:	https://vuxml.FreeBSD.org/freebsd/d3324fdb-6bf0-11e5-bc5e-00505699053e.html

Changes:
  head/security/vuxml/vuln.xml
Comment 6 Jason Unovitch freebsd_committer freebsd_triage 2015-10-30 03:21:18 UTC
Ping.  Is there a documented reason this hasn't been MFH'd yet?

Portsmon is showing this as building all green across the board.
http://portsmon.freebsd.org/portoverview.py?category=www&portname=zend-framework1
Comment 7 Jason Unovitch freebsd_committer freebsd_triage 2015-12-01 00:50:50 UTC
Any update on merge-quarterly?
Comment 8 Jason Unovitch freebsd_committer freebsd_triage 2015-12-15 02:21:36 UTC
Any update?
Comment 9 Jason Unovitch freebsd_committer freebsd_triage 2016-01-03 02:41:44 UTC
Close PR with regards to merge-quarterly? as it's 2016 now.  Let set as is as there was no feedback there but mark the PR closed/fixed as the main commits in head were all done.