Zend Framework: SQL injection A vulnerability in Zend Framework could allow a remote attacker to inject SQL commands. ZendFramework 2014-08-04 2014-08-04 369139 remote 1.11.6 1.11.6

Zend Framework is a high quality and open source framework for developing Web Applications.

Developers using non-ASCII-compatible encodings in conjunction with the MySQL PDO driver of PHP may be vulnerable to SQL injection attacks.

A remote attacker could use specially crafted input to execute arbitrary SQL statements.

There is no known workaround at this time.

All ZendFramework users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-php/ZendFramework-1.11.6"

NOTE: This is a legacy GLSA. Updates for all affected architectures have been available since 2011-06-07. It is likely that your system is already updated to no longer be affected by this issue.

CVE-2011-1939 craig K_F