Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 449568 (CVE-2012-6431) - dev-php/symfony : multiple vulnerabilities (CVE-2012-{6431,6432})
Summary: dev-php/symfony : multiple vulnerabilities (CVE-2012-{6431,6432})
Status: RESOLVED INVALID
Alias: CVE-2012-6431
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-01 12:24 UTC by Agostino Sarubbo
Modified: 2013-09-11 10:31 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-01-01 12:24:52 UTC
From https://secunia.com/advisories/51660/ :

Description
A vulnerability has been reported in Symfony, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to an error when handling URL-encoded paths and can be exploited to bypass a security rule by using double-URL-encoded paths.

The vulnerability is reported in versions 2.0.0 through 2.0.19.


Solution
Update to version 2.0.20.

From https://secunia.com/advisories/51662/ :

Description
A vulnerability has been reported in Symfony, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to an error when handling _internal routes via the "render" tag and can be exploited to execute arbitrary Controller or Services by using a specially crafted path.

Successful exploitation requires _internal routes to be enabled.

The vulnerability is reported in all 2.0.x and 2.1.x versions.


Solution
Please see the vendor's advisory for recommended workarounds.

Provided and/or discovered by
The vendor credits Victor Berchet.

Original Advisory
http://symfony.com/blog/security-release-symfony-2-0-20-and-2-1-5-released


@maintainer:
Since 1.x is not anymore supported you need to check if the latter is valid.
Comment 1 Ole Markus With (RETIRED) gentoo-dev 2013-09-11 10:14:30 UTC
Both of these issues are not valid. Besides, symfony has been masked for removal anyways.
Comment 2 Sergey Popov (RETIRED) gentoo-dev 2013-09-11 10:31:31 UTC
(In reply to Ole Markus With from comment #1)
> Both of these issues are not valid. Besides, symfony has been masked for
> removal anyways.

Yep, we have no vulnerable versions of symfony in tree