Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 222943 - dev-php5/symfony <1.0.16 remote form validation bypass
Summary: dev-php5/symfony <1.0.16 remote form validation bypass
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://trac.symfony-project.com/ticke...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-05-20 10:14 UTC by Jamie Learmonth
Modified: 2008-07-31 23:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jamie Learmonth 2008-05-20 10:14:50 UTC
symfony 1.0.11 has a remote form validation bypass on case sensitive operating systems.

http://trac.symfony-project.com/ticket/1617

Upgrading to 1.0.16 resolves the issue.

Reproducible: Always
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-05-22 08:32:16 UTC
Is this validator supposed to be used as a security mechanism?
Comment 2 Christian Hoffmann (RETIRED) gentoo-dev 2008-07-01 19:46:50 UTC
Well, I dont know who is expected to comment here. As nobody else did, I'm replying, but I don't have any real new information, sorry.

From my reading of the upstream ticket, I'd say yes, this validator looks like a security measure (and is very likely to be the only hurdle against any attacks, as far as I can see).
I could bump symfony if you beat me to, but I have no easy way to test it. Anyone around for testing?

CC'ing webapps, maybe they know of any test procedures or want to take over the package. :P
Comment 3 Gunnar Wrobel (RETIRED) gentoo-dev 2008-07-31 20:17:32 UTC
Moved package to webapps herd. Bumped to 1.0.16. Unstable on all archs. Removed vulnerable versions. webapps done.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-07-31 20:43:03 UTC
thanks, closing without glsa.