Skip to content
This repository

[ZF-11839] fixed security issue (possible password disclosure) #526

Closed
wants to merge 39 commits into from

2 participants

Stefan Gehrig Matthew Weier O'Phinney
Stefan Gehrig

1.11-fix ported to ZF2

added some commits July 31, 2010
Stefan Gehrig updateing 7f7c19d
Stefan Gehrig Revert "updateing"
This reverts commit 7f7c19da825c7771f685ba594b506414bf8e9cb4.
90a5225
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 d46a241
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 cd3deb5
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 c7c402a
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 7a661fa
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 b26807b
Stefan Gehrig test 7927a0f
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 7c309bf
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 e494b38
Stefan Gehrig Merge branch 'master' of github.com:sgehrig/zf2 2c50897
Stefan Gehrig deleted HTTPTest f1e045f
Stefan Gehrig Merge branch 'master', remote branch 'zf2/master' 47e0377
Stefan Gehrig Merge branch 'master' of github.com:sgehrig/zf2 70492e4
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 9cb3a2d
Stefan Gehrig added .DS_Store to .gitignore
Signed-off-by: Stefan Gehrig <gehrig@ishd.de>
17bdc38
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 37995a5
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 722664e
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 bebe1bf
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 4dc9a11
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 03b8abd
Stefan Gehrig Merge branch 'master' of github.com:sgehrig/zf2 e8d1313
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 08c06c8
Stefan Gehrig Merge remote branch 'origin/master' c7e6a11
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 cf35376
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 8aea678
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 5aad269
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 3df55f1
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 f21ba83
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 fa582ca
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 6cc59ca
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 4c938d8
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 010bbb8
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 c93d1ef
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 dc8907c
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2
Conflicts:
	.gitignore
0b5d964
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 671ba15
Stefan Gehrig [ZF-11839] fixed security problem (possible password disclosure) 28ff442
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 188816b
Matthew Weier O'Phinney

Reviewed, merged, and pushed to master. In the future, do your fixes/features on discrete branches, to ensure we don't get spurious commits by accident. :)

Matthew Weier O'Phinney weierophinney closed this October 26, 2011
Stefan Gehrig
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Showing 39 unique commits by 1 author.

Jul 31, 2010
Stefan Gehrig updateing 7f7c19d
Stefan Gehrig Revert "updateing"
This reverts commit 7f7c19da825c7771f685ba594b506414bf8e9cb4.
90a5225
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 d46a241
Aug 12, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 cd3deb5
Aug 23, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 c7c402a
Sep 22, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 7a661fa
Oct 05, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 b26807b
Stefan Gehrig test 7927a0f
Nov 03, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 7c309bf
Nov 13, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 e494b38
Stefan Gehrig Merge branch 'master' of github.com:sgehrig/zf2 2c50897
Nov 25, 2010
Stefan Gehrig deleted HTTPTest f1e045f
Stefan Gehrig Merge branch 'master', remote branch 'zf2/master' 47e0377
Stefan Gehrig Merge branch 'master' of github.com:sgehrig/zf2 70492e4
Dec 02, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 9cb3a2d
Dec 07, 2010
Stefan Gehrig added .DS_Store to .gitignore
Signed-off-by: Stefan Gehrig <gehrig@ishd.de>
17bdc38
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 37995a5
Dec 14, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 722664e
Dec 20, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 bebe1bf
Dec 29, 2010
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 4dc9a11
Jan 11, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 03b8abd
Stefan Gehrig Merge branch 'master' of github.com:sgehrig/zf2 e8d1313
Jan 30, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 08c06c8
Stefan Gehrig Merge remote branch 'origin/master' c7e6a11
Feb 02, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 cf35376
Feb 03, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 8aea678
Feb 05, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 5aad269
Feb 24, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 3df55f1
Mar 02, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 f21ba83
Mar 08, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 fa582ca
Mar 09, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 6cc59ca
Mar 23, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 4c938d8
Apr 01, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 010bbb8
Apr 19, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 c93d1ef
May 05, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 dc8907c
Jul 29, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2
Conflicts:
	.gitignore
0b5d964
Oct 20, 2011
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 671ba15
Oct 24, 2011
Stefan Gehrig [ZF-11839] fixed security problem (possible password disclosure) 28ff442
Stefan Gehrig Merge branch 'master' of git://github.com/zendframework/zf2 188816b
This page is out of date. Refresh to see the latest.
2  library/Zend/Authentication/Adapter/Ldap.php
@@ -365,7 +365,7 @@ public function authenticate()
365 365
                 } else {
366 366
                     $line = $zle->getLine();
367 367
                     $messages[] = $zle->getFile() . "($line): " . $zle->getMessage();
368  
-                    $messages[] = str_replace($password, '*****', $zle->getTraceAsString());
  368
+                    $messages[] = preg_replace('/\b'.preg_quote($password, '/').'\b/', '*****', $zle->getTraceAsString());
369 369
                     $messages[0] = 'An unexpected failure occurred';
370 370
                 }
371 371
                 $messages[1] = $zle->getMessage();
Commit_comment_tip

Tip: You can add notes to lines in a file. Hover to the left of a line to make a note

Something went wrong with that request. Please try again.