Today a patch from #Magento 1.9.0.0 got merged into #ZF1Future:
https://github.com/Shardj/zf1-future/pull/296
Thanks to Sven for this PR!
This is why it was important to remove the patched #ZendFramework from #OpenMage's core and move to composer!
#OpenMage #zendframework #zf1future #magento
RCE ‘Bug’ Found and Disputed in Popular PHP Scripting Framework - Impacted are PHP-based websites running a vulnerable version of the web-app creation tool Zend Fra... https://threatpost.com/rce-bug-php-scripting-framework/162773/ #remotecodeexecution #scriptingframework #vulnerabilities #laminasproject #zendframework #websecurity #github #bug #php #rce
#rce #php #bug #github #websecurity #zendframework #laminasproject #vulnerabilities #scriptingframework #remotecodeexecution
RT @benjamincremer
I'm calling bullshit on the #zendframework / @getlaminas CVE floating around. Using unserialize on untrusted user input is always flawed and not specific to a framework vuln. Here is a good read on that topic https://medium.com/swlh/exploiting-php-deserialization-56d71f03282a
RT @zfdevteam@twitter.com
Linux Foundation to lead the next phase of growth for #ZendFramework.
Find out more about the project and how you can become a project sponsor.
@linuxfoundation@twitter.com #Laminas
🐦🔗: https://twitter.com/zfdevteam/status/1118514727955644416