Bug 1186600 - php-ZendFramework2: ZF2015-01: Session validation vulnerability
Summary: php-ZendFramework2: ZF2015-01: Session validation vulnerability
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1186601 1186602
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-01-28 06:02 UTC by Kurt Seifried
Modified: 2019-09-29 13:27 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-07-29 21:44:19 UTC
Embargoed:


Attachments (Terms of Use)

Description Kurt Seifried 2015-01-28 06:02:36 UTC
Zend.com reports:

ZF2015-01: Session validation vulnerability
Zend\Session session validators do not work as expected if set prior to the start of a session.

External Reference:
http://framework.zend.com/security/advisory/ZF2015-01

Comment 1 Kurt Seifried 2015-01-28 06:04:39 UTC
Created php-ZendFramework2 tracking bugs for this issue:

Affects: fedora-all [bug 1186601]
Affects: epel-all [bug 1186602]

Comment 2 Fedora Update System 2015-02-02 17:05:28 UTC
php-ZendFramework2-2.3.4-1.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 3 Shawn Iwinski 2015-07-20 02:11:10 UTC
All dependent bugs have been closed, can this tracking bug be closed as well?


Note You need to log in before you can comment on or make changes to this bug.