Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 21: FEDORA-2015-9039 Critical: php-symfony HTTP Kernel Issue

fedora
Calendar Grey June 6, 2015
Dist Fedora Esm H88
Fedora 21 has released a security update for the PHP-Symfony framework, addressing CVE-2015-4050, which enhances the FragmentListener security and mitigates risks
**2.5.12** (2015-05-27) * security #14759 CVE-2015-4050 [HttpKernel] Do not call the FragmentListener if _controller is already defined (jakzal)

Summary

PHP framework for web projects

Update Information:

**2.5.12** (2015-05-27) * security #14759 CVE-2015-4050 [HttpKernel] Do not call the FragmentListener if _controller is already defined (jakzal)

Change Log

* Wed May 27 2015 Remi Collet - 2.5.12-1 - Update to 2.5.12 - security fix for CVE-2015-4050 * Thu Apr 2 2015 Remi Collet - 2.5.11-1 - Update to 2.5.11 - security fix for CVE-2015-2308 and CVE-2015-2309 * Wed Mar 18 2015 Remi Collet - 2.5.10-1 - Update to 2.5.10 * Mon Dec 15 2014 Remi Collet - 2.5.8-1 - Update to 2.5.8 * Thu Nov 20 2014 Shawn Iwinski - 2.5.7-1 - Updated to 2.5.7 (BZ #1166396) - Added php-composer(egulias/email-validator) dependency

References


[ 1 ] Bug #1227264 - CVE-2015-4050 php-symfony: ESI unauthorized access https://bugzilla.redhat.com/show_bug.cgi?id=1227264

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update php-symfony' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: php-symfony
Product: Fedora 21
Version: 2.5.12
Release: 1.fc21
Summary: PHP framework for web projects

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here