CVE-2014-8088
22.10.2014, 14:55
The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.Enginsight
Vendor | Product | Version |
---|---|---|
zend | zend_framework | 𝑥 ≤ 1.12.7 |
zend | zend_framework | 1.12.0 |
zend | zend_framework | 1.12.0:rc1 |
zend | zend_framework | 1.12.0:rc2 |
zend | zend_framework | 1.12.0:rc3 |
zend | zend_framework | 1.12.0:rc4 |
zend | zend_framework | 1.12.1 |
zend | zend_framework | 1.12.2 |
zend | zend_framework | 1.12.3 |
zend | zend_framework | 1.12.5 |
zend | zend_framework | 2.0.0 |
zend | zend_framework | 2.01 |
zend | zend_framework | 2.2.2 |
zend | zend_framework | 2.2.3 |
zend | zend_framework | 2.2.4 |
zend | zend_framework | 2.2.5 |
zend | zend_framework | 2.2.6 |
zend | zend_framework | 2.2.7 |
zend | zend_framework | 2.3.0 |
zend | zend_framework | 2.3.1 |
zend | zend_framework | 2.3.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
zend-framework |
| ||||||||||||||||||||||||||||||||||||||||||
zendframework |
|
Common Weakness Enumeration
References