drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Eingabeprüfung in php-symfony2-HttpFoundation
Name: |
Mangelnde Eingabeprüfung in php-symfony2-HttpFoundation |
|
ID: |
FEDORA-2013-14608 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 19 |
|
Datum: |
Mi, 21. August 2013, 08:33 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4752 |
|
Applikationen: |
symfony |
|
Originalnachricht |
Name : php-symfony2-HttpFoundation Product : Fedora 19 Version : 2.2.5 Release : 1.fc19 URL : index.html Summary : Symfony2 HttpFoundation Component Description : The HttpFoundation Component defines an object-oriented layer for the HTTP specification.
In PHP, the request is represented by some global variables ($_GET, $_POST, $_FILE, $_COOKIE, $_SESSION...) and the response is generated by some functions (echo, header, setcookie, ...).
The Symfony2 HttpFoundation component replaces these default PHP global variables and functions by an Object-Oriented layer.
Optional dependencies: memcache, memcached, mongo
------------------------------------------------------------------------------- - Update Information:
Updated to 2.2.5
CVE-2013-4752 Request::getHost() poisioning
Release blog posts:
* http://symfony.com/blog/symfony-2-2-4-released
* security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released
Full change log: https://github.com/symfony/symfony/blob/v2.2.5/CHANGELOG-2.2.md ------------------------------------------------------------------------------- - ChangeLog:
* Fri Aug 9 2013 Shawn Iwinski <shawn.iwinski@gmail.com> 2.2.5-1 - Updated to 2.2.5 * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.2.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Tue Jul 2 2013 Shawn Iwinski <shawn.iwinski@gmail.com> 2.2.3-2 - Merge master, f19, f18, and el6 (temp disable tests for el6) * Tue Jul 2 2013 Shawn Iwinski <shawn.iwinski@gmail.com> 2.2.3-1 - Updated to 2.2.3 * Thu Jun 13 2013 Shawn Iwinski <shawn.iwinski@gmail.com> 2.2.2-1 - Updated to 2.2.2 - Removed package.xml modifications fixed usptream ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #995583 - CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning https://bugzilla.redhat.com/show_bug.cgi?id=995583 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update php-symfony2-HttpFoundation' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|