Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport of fix for CVE-2021-3007 in Zend_Http_Response_Stream #127

Merged
merged 2 commits into from
Jan 12, 2021
Merged

Backport of fix for CVE-2021-3007 in Zend_Http_Response_Stream #127

merged 2 commits into from
Jan 12, 2021

Conversation

lmcnearney
Copy link

Only the actual fix was brought over as I didn't see an applicable unit test to extend for ZF1.

@lmcnearney
Copy link
Author

Added backported test from @glensc and cleaned up my original commit message.

@Shardj Shardj merged commit 1c70c67 into Shardj:master Jan 12, 2021
@Shardj
Copy link
Owner

Shardj commented Jan 12, 2021

Thanks

@SvenRtbg
Copy link

Do you mind releasing this in the near future? It addresses a CVE vulnerability, and even though the change itself looks minor, I'd apprechiate an updated release.

Not wanting to put too many details in here, but the underlying problem seems to be a deserialization issue in some other software, leveraging the Zend HTTP stream object - and this can be triggered even if the class simply exists without being used.

@Shardj
Copy link
Owner

Shardj commented Jan 25, 2021

Sure thing @SvenRtbg it'll be out in 10 minutes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants