Fedora alert FEDORA-2021-c57937ab9f (php-symfony3)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 34 Update: php-symfony3-3.4.49-1.fc34 | |
Date: | Sat, 29 May 2021 01:06:20 +0000 | |
Message-ID: | <20210529010620.5CF8430CC2D1@bastion01.iad2.fedoraproject.org> | |
Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2021-c57937ab9f 2021-05-29 01:04:01.502342 -------------------------------------------------------------------------------- Name : php-symfony3 Product : Fedora 34 Version : 3.4.49 Release : 1.fc34 URL : https://symfony.com Summary : Symfony PHP framework (version 3) Description : Symfony PHP framework (version 3). NOTE: Does not require PHPUnit bridge. -------------------------------------------------------------------------------- Update Information: **Version 3.4.49** (2021-05-19) * security **CVE-2021-21424** [Security\Core] Fix user enumeration via response body on invalid credentials (chalasr) ---- **Version 3.4.48** (2021-05-12) * security **CVE-2021-21424** [Security][Guard] Prevent user enumeration (chalasr) -------------------------------------------------------------------------------- ChangeLog: * Wed May 19 2021 Remi Collet <remi@remirepo.net> - 3.4.49-1 - update to 3.4.49 * Mon May 17 2021 Remi Collet <remi@remirepo.net> - 3.4.48-1 - update to 3.4.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1960631 - CVE-2021-21424 php-symfony: user enumeration in authentication mechanisms [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1960631 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c57937ab9f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure