|
|
Log in / Subscribe / Register

Debian alert DLA-4200-1 (symfony)

From:  Guilhem Moulin <guilhem@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4200-1] symfony security update
Date:  Sat, 31 May 2025 21:35:26 +0200
Message-ID:  <aDtZ_k__PZgeBxDE@debian.org>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4200-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin May 31, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : symfony Version : 4.4.19+dfsg-2+deb11u7 CVE ID : CVE-2024-50343 CVE-2024-50345 Security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lead to validation bypass or open redirects. CVE-2024-50343 It was discovered input ending with `\n` could bypass Validators. CVE-2024-50345 Sam Mush discovered that due to URI parsing mismatch between common browsers and the Request class, an attacker could supply a specially crafted URI to bypass validation and redirect users to another domain. For Debian 11 bullseye, these problems have been fixed in version 4.4.19+dfsg-2+deb11u7. We recommend that you upgrade your symfony packages. For the detailed security status of symfony please refer to its security tracker page at: https://security-tracker.debian.org/tracker/symfony Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmg7Wf4ACgkQ05pJnDwh pVKHfxAAgMm9uNV/CMMdgc30teh1/3lf/FnVLnKLL4qWmtVu21WuX1nHScD8iFy/ Mnnouirgo3hkRTY/Uj24YhcauOIDbdiGg6yc6oz6MHccr3Uu2+TH2ZVyGoTML8/9 gfFLnXA/5RHSkDUPIcSWrN7mQH3vfj14VSkDhlMw1W5XUEQSdn6WcjOyxvoUzoQX PCYVzyI6ehw5mDC34Ia87/faZ0KaWFFaEevclvXtqrDxphGr4gDeB0enh5yGL+TI VoTzP8LxBRtNwPKkUa+n4/N+q+04G9EQ+QpKgkj9Y0++f3UiiZZegZrGSzBM6wUX UllFCUPPg9nh1xgCA1/cX+CPXnHmbciAjJw/HInQXHPj9lygwu05dgxzyRjIaBFn SgVTcBZe60lC5iqZgbn93Gn7J28obwB3MjLwUO9rWoRAR/QX9adjczw4AIDFBa6U YiXXfDK4evkSWiC9sbtHXQOtJ3eCFXNtJC58cDVhDUcejp9IGo5bJGSpUXQtTqzw 1WGMWQaSt2TPYrY6Nzqwxh08EfeKO+AddPjan0jnYa7CStv0utOsmjEUJX4kFfa8 jOC0U4wVBUYGpcfSkRDwyX2j6o61/LUTZP4mU6fMVeM24k6uGCYp43H2+Nz6t2x9 U7q2di+ctI2V1fLW2DaexXJ0CUYAeZw0Ri3u9LHexbSrvHVNT/s= =iK1v -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds