Skip to content
This repository has been archived by the owner on May 16, 2018. It is now read-only.

Zend Framework 1.12.12

Compare
Choose a tag to compare
@weierophinney weierophinney released this 19 May 17:51
· 136 commits to master since this release

SECURITY UPDATES

  • ZF2015-04: Zend_Mail and Zend_Http were both susceptible to CRLF Injection Attack vectors (for HTTP, this is often referred to as HTTP Response Splitting). Both components were updated to perform header value validations to ensure no values contain characters not detailed in their corresponding specifications, and will raise exceptions on detection. Each also provides new facilities for both validating and filtering header values prior to injecting them into header classes. If you use either Zend_Mail or Zend_Http, we recommend upgrading immediately.