Zend Core Updates
Info
Mar-2009: The Core development team announces the immediate availability of Core Update 2.5.2-3;
This update includes the following changes:
Upgrade cUrl library to version 7.19.4 .
Problem description:
Security exploit was discovered in cUrl, allowing server to redirect cUrl into a client local file Impact :
malicious server can make the client expose or overwrit local file when client attempts to upload or tansfer data.
Severity :
medium
Recommendation :
upgrade cUrl to 7.19.4 and rebuild the cUrl extension (staticly).
Upgrade libevent library to version 1.4.9 .
Various bug fixes.
All Zend Core users are encouraged to upgrade to this update.
Changes since 2.5.0
| Component | Status | Old Version | New Version |
| ZendCoreInstaller | UPD | 2.0-1 | 2.0-4 |
| PHP | UPD | 5.2.4-1 | 5.2.9-1 |
| Apache Support | UPD | 5.2.4-1 | 5.2.9-1 |
| Apache/EAPI Support | UPD | 5.2.4-1 | 5.2.9-1 |
| Apache/SSL Support | UPD | 5.2.4-1 | 5.2.9-1 |
| Apache2 Support | UPD | 5.2.4-1 | 5.2.9-1 |
| Apache22 Support | UPD | 5.2.4-1 | 5.2.9-1 |
| PEAR | UPD | 5.2.4-1 | 5.2.9-1 |
| ZendExtensionManager | UPD | 1.0.10-1 | 1.2.0-1 |
| ZendOptimizer | UPD | 3.3.1-1 | 3.3.7-1 |
| ZendDebugger | UPD | 5.2.10-1 | 5.2.18-2 |
| ext/bcmath | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/bz2 | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/calendar | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/curl | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/exif | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/ftp | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/gd | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/gmp | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/ibm_db2 | UPD | 1.6.2-1 | 1.8.1-1 |
| ext/iconv | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/imap | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/ldap | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/mbstring | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/mcrypt | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/mhash | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/ming | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/pcntl | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/posix | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/shmop | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/soap | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/sockets | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/sysvmsg | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/sysvsem | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/sysvshm | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/tidy | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/tokenizer | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/xmlreader | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/xmlwriter | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/xsl | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/zip | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/pdo | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/pdo_mysql | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/pdo_pgsql | UPD | 5.2.4-1 | 5.2.9-1 |
| lib/openssl | UPD | 0.9.8-1 | 0.9.8-5 |
| lib/curl | UPD | 7.16.0-1 | 7.19.4-1 |
| lib/xml2 | UPD | 2.6.27-1 | 2.7.3-1 |
| lib/openldap | UPD | 2.3.27-1 | 2.4.11-1 |
| ext/oci8 | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/mysql | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/mysqli | UPD | 5.2.4-1 | 5.2.9-1 |
| ext/pdo_ibm | UPD | 1.2.3-1 | 1.2.3-4 |
| ext/gettext | NEW | N/A | 5.2.9-1 |
| ext/pdo_sqlite | NEW | N/A | 5.2.9-1 |
| ext/memcache | NEW | N/A | 5.2.9-2 |
| ext/xmlrpc | NEW | N/A | 5.2.9-1 |
| ext/pdo_informix | NEW | N/A | 5.2.9-1 |
| lib/sqlite | NEW | N/A | 3.0.8-1 |
| lib/gettext | NEW | N/A | 0.17 |
| lib/expat | NEW | N/A | 2.0.0-1 |
| lib/informix | NEW | N/A | 1.0-1 |
