Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in php-symfony
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in php-symfony
ID: FEDORA-2015-9039
Distribution: Fedora
Plattformen: Fedora 21
Datum: Sa, 6. Juni 2015, 11:59
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4050
Applikationen: symfony

Originalnachricht

Name        : php-symfony
Product : Fedora 21
Version : 2.5.12
Release : 1.fc21
URL : http://symfony.com
Summary : PHP framework for web projects
Description :
PHP framework for web projects

-------------------------------------------------------------------------------
-
Update Information:

**2.5.12** (2015-05-27)
* security #14759 CVE-2015-4050 [HttpKernel] Do not call the FragmentListener
if _controller is already defined (jakzal)

-------------------------------------------------------------------------------
-
ChangeLog:

* Wed May 27 2015 Remi Collet <remi@fedoraproject.org> - 2.5.12-1
- Update to 2.5.12
- security fix for CVE-2015-4050
* Thu Apr 2 2015 Remi Collet <remi@fedoraproject.org> - 2.5.11-1
- Update to 2.5.11
- security fix for CVE-2015-2308 and CVE-2015-2309
* Wed Mar 18 2015 Remi Collet <remi@fedoraproject.org> - 2.5.10-1
- Update to 2.5.10
* Mon Dec 15 2014 Remi Collet <remi@fedoraproject.org> - 2.5.8-1
- Update to 2.5.8
* Thu Nov 20 2014 Shawn Iwinski <shawn.iwinski@gmail.com> - 2.5.7-1
- Updated to 2.5.7 (BZ #1166396)
- Added php-composer(egulias/email-validator) dependency
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1227264 - CVE-2015-4050 php-symfony: ESI unauthorized access
https://bugzilla.redhat.com/show_bug.cgi?id=1227264
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update php-symfony' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung