Vulnerability Bulletins

DSA-3340 zendframework - security update

   
Affected software Debian
 
Dawid Golunski discovered that when running under PHP-FPM in a threadedenvironment, Zend Framework, a PHP framework, did not properly handleXML data in multibyte encoding. This could be used by remote attackersto perform an XML External Entity attack via crafted XML data.

More info:

https://www.debian.org/security/2015/dsa-3340