Bug 28198 - ZendFramework dead upstream?
Summary: ZendFramework dead upstream?
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: High normal
Target Milestone: ---
Assignee: All Packagers
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-01-22 23:17 CET by David Walser
Modified: 2021-01-28 00:03 CET (History)
2 users (show)

See Also:
Source RPM: php-zendframework-zend-* php-ZendFramework2*
CVE:
Status comment:


Attachments

Description David Walser 2021-01-22 23:17:25 CET
There is a disputed CVE that has received attention in the press recently, due to it being actively exploited to create a botnet called FreakOut!:
https://nvd.nist.gov/vuln/detail/CVE-2021-3007

The description there says that ZendFramework is no longer maintained.

We have several of these packages.  Do we need to remove them all?
David Walser 2021-01-22 23:17:32 CET

Priority: Normal => release_blocker

Comment 1 Lewis Smith 2021-01-23 18:12:11 CET
See no choice but to assign this to everybody for comment.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Lécureuil 2021-01-23 18:27:23 CET
They are not nedeed by anything so i am not against removing them.

CC: (none) => mageia

Comment 3 Frédéric "LpSolit" Buclin 2021-01-25 22:49:51 CET
Drupal replaced all its ZendFramework dependencies by Laminas ones because ZendFramework is indeed abandoned, see:

https://www.drupal.org/project/drupal/issues/3104015

So it's probably a good idea to kill it entirely before releasing Mageia 8. They can be replaced by Laminas if needed.
Comment 4 Nicolas Lécureuil 2021-01-26 11:54:06 CET
adding it in task obsolete.
Comment 5 David Walser 2021-01-26 16:32:14 CET
There are some left over:
php-laminas-zendframework-bridge-1.1.1-1.mga8.noarch.rpm
php-zendframework-zend-console-2.8.0-2.mga8.noarch.rpm
php-zendframework-zend-i18n-2.10.1-2.mga8.noarch.rpm
php-zendframework-zend-json-3.1.2-2.mga8.noarch.rpm
php-zendframework-zend-loader-2.6.1-2.mga8.noarch.rpm
php-zendframework-zend-serializer-2.9.1-2.mga8.noarch.rpm
Comment 6 Dave Hodgins 2021-01-27 23:41:05 CET
Ping.
php-laminas-zendframework-bridge-1.1.1-1.mga8.src.rpm
php-zendframework-zend-console-2.8.0-2.mga8.src.rpm
php-zendframework-zend-i18n-2.10.1-2.mga8.src.rpm
php-zendframework-zend-json-3.1.2-2.mga8.src.rpm
php-zendframework-zend-loader-2.6.1-2.mga8.src.rpm
php-zendframework-zend-serializer-2.9.1-2.mga8.src.rpm

Are still present on the mirrors.

Lowering the priority slightly as none of these packages are on any of
the iso images.

They could be removed by task-obsolete or task-null post release.

CC: (none) => davidwhodgins
Priority: release_blocker => High

Comment 7 Nicolas Lécureuil 2021-01-28 00:03:32 CET
fixed.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.