Upstream Zend Framework 1.7.5 contains a security fix for a potential Local File Inclusion (LFI) vulnerability in the Zend_View::render() method. This fixed is tagged upstream as "controversial", as it breaks backwards compatibility and existing uses of method. See references for further details. References: http://devzone.zend.com/article/4266-Zend-Framework-1.7.5-Released http://weierophinney.net/matthew/archives/206-Zend-Framework-1.7.5-Released-Important-Note-Regarding-Zend_View.html http://framework.zend.com/manual/en/zend.view.migration.html http://bugs.gentoo.org/show_bug.cgi?id=259512
php-ZendFramework-1.7.7-2.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/php-ZendFramework-1.7.7-2.fc10
php-ZendFramework-1.7.7-1.fc9 has been submitted as an update for Fedora 9. http://admin.fedoraproject.org/updates/php-ZendFramework-1.7.7-1.fc9
php-ZendFramework-1.7.7-2.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.