Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 30: 2019-9c2ad3b018 Critical: Php-Symfony Upgrade Announcement

fedora
Calendar Grey November 21, 2019
Dist Fedora Esm H88
A new update for php-symfony has been released to address urgent vulnerabilities concerning mime-type detection and UriSigner functionality.
**Version 2.8.52** (2019-11-13) * security #cve-2019-18888 [HttpFoundation] fix guessing mime-types of files with leading dash (nicolas-grekas) * security #cve-2019-18887 [HttpKer...

Summary

PHP framework for web projects

**Version 2.8.52** (2019-11-13) * security #cve-2019-18888 [HttpFoundation]

fix guessing mime-types of files with leading dash (nicolas-grekas) * security

#cve-2019-18887 [HttpKernel] Use constant time comparison in UriSigner (stof)

* Wed Nov 13 2019 Remi Collet - 2.8.52-1

- update to 2.8.52

* Fri Jul 26 2019 Fedora Release Engineering - 2.8.51-3

- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild

* Wed Jun 19 2019 Shawn Iwinski - 2.8.51-2

- Disable tests by default (follows php-symfony3 and php-symfony4 pkgs)

- Always require build dependencies

- Use range version dependencies for Fedora >= 27 || RHEL >= 8

- Bump psr/log min version to 1.0.1 so php-composer(psr/log) virtual provide can be used

* Thu Apr 18 2019 Remi Collet - 2.8.51-1

- update to 2.8.51

su -c 'dnf upgrade --advisory FEDORA-2019-9c2ad3b018' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 2.8.52
Release: 1.fc30
Summary: PHP framework for web projects

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here