Zend Core Updates
Info
Mar-2009: The Core development team announces the immediate availability of Core Update 2.5.2-3;
This update includes the following changes:
Upgrade cUrl library to version 7.19.4 .
Problem description:
Security exploit was discovered in cUrl, allowing server to redirect cUrl into a client local file Impact :
malicious server can make the client expose or overwrit local file when client attempts to upload or tansfer data.
Severity :
medium
Recommendation :
upgrade cUrl to 7.19.4 and rebuild the cUrl extension (staticly).
Upgrade libevent library to version 1.4.9 .
Various bug fixes.
All Zend Core users are encouraged to upgrade to this update.
Changes since 2.5.2
| Component | Status | Old Version | New Version |
| PHP | UPD | 5.2.6-2 | 5.2.9-1 |
| Apache Support | UPD | 5.2.6-2 | 5.2.9-1 |
| Apache/EAPI Support | UPD | 5.2.6-2 | 5.2.9-1 |
| Apache/SSL Support | UPD | 5.2.6-1 | 5.2.9-1 |
| Apache2 Support | UPD | 5.2.6-2 | 5.2.9-1 |
| Apache22 Support | UPD | 5.2.6-2 | 5.2.9-1 |
| PEAR | UPD | 5.2.6-1 | 5.2.9-1 |
| ZendOptimizer | UPD | 3.3.6-1 | 3.3.7-1 |
| ZendDebugger | UPD | 5.2.15-1 | 5.2.18-2 |
| ext/bcmath | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/bz2 | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/calendar | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/curl | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/exif | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/ftp | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/gd | UPD | 5.2.6-2 | 5.2.9-1 |
| ext/gmp | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/gettext | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/ibm_db2 | UPD | 1.6.2-4 | 1.8.1-1 |
| ext/iconv | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/imap | UPD | 5.2.6-2 | 5.2.9-1 |
| ext/ldap | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/mbstring | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/mcrypt | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/mhash | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/ming | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/pcntl | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/posix | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/shmop | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/soap | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/sockets | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/sysvmsg | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/sysvsem | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/sysvshm | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/tidy | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/tokenizer | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/xmlreader | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/xmlwriter | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/xsl | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/zip | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/pdo | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/pdo_ibm | UPD | 1.2.3-2 | 1.2.3-4 |
| ext/pdo_mysql | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/pdo_pgsql | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/pdo_sqlite | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/oci8 | UPD | 5.2.6-2 | 5.2.9-1 |
| ext/mysql | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/mysqli | UPD | 5.2.6-1 | 5.2.9-1 |
| ext/memcache | UPD | 5.2.6-2 | 5.2.9-2 |
| ext/xmlrpc | UPD | 5.2.6-1 | 5.2.9-1 |
| lib/openssl | UPD | 0.9.8-4 | 0.9.8-5 |
| lib/curl | UPD | 7.18.1-1 | 7.19.4-1 |
| lib/xml2 | UPD | 2.6.27-1 | 2.7.3-1 |
| ext/pdo_informix | NEW | N/A | 5.2.9-1 |
| lib/informix | NEW | N/A | 1.0-1 |
