**Version 4.1.12** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [Cache][PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-32067d8b15 2019-04-27 23:10:05.598341 --------------------------------------------------------------------------------Name : php-symfony4 Product : Fedora 29 Version : 4.1.12 Release : 1.fc29 URL : https://symfony.com Summary : Symfony PHP framework (version 4) Description : Symfony PHP framework (version 4). NOTE: Does not require PHPUnit bridge. --------------------------------------------------------------------------------Update Information: **Version 4.1.12** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [Cache][PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security #cve-2019-10911 [Security] Add a separator in the remember me cookie hash (pborreli) * security #cve-2019-10913 [HttpFoundation] reject invalid method override (nicolas-grekas) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 18 2019 Remi Collet - 4.1.12-1 - update to 4.1.12 * Mon Feb 4 2019 Remi Collet - 4.1.11-1 - update to 4.1.11 - raise dependency on twig 1.37.1 * Sat Feb 2 2019 Fedora Release Engineering - 4.1.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Jan 7 2019 Remi Collet - 4.1.10-1 - update to 4.1.10 * Fri Dec 7 2018 Remi Collet - 4.1.9-1 - updateto 4.1.9 * Tue Nov 27 2018 Remi Collet - 4.1.8-1 - update to 4.1.8 * Mon Nov 5 2018 Remi Collet - 4.1.7-1 - update to 4.1.7 * Thu Oct 18 2018 Remi Collet - 4.1.6-2 - ignore doctrine/data-fixtures version * Wed Oct 3 2018 Remi Collet - 4.1.6-1 - update to 4.1.6 * Mon Oct 1 2018 Remi Collet - 4.1.5-1 - update to 4.1.5 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-32067d8b15' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-3ee6a7adf2 2019-04-27 21:35:40.510401 --------------------------------------------------------------------------------Name : php-symfony Product : Fedora 28 Version : 2.8.51 Release : 1.fc28 URL : https://symfony.com Summary : PHP framework for web projects Description : PHP framework for web projects --------------------------------------------------------------------------------Update Information: **Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security #cve-2019-10911 [Security] Add a separator in the remember me cookie hash (pborreli) * security #cve-2019-10913 [HttpFoundation] reject invalid method override (nicolas-grekas) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 18 2019 Remi Collet - 2.8.51-1 - update to 2.8.51 * Sat Feb 2 2019 Fedora Release Engineering - 2.8.49-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Fri Dec 7 2018 Remi Collet - 2.8.49-1 - update to 2.8.49 * Tue Nov 27 2018 Remi Collet - 2.8.48-1 - update to 2.8.48 * Mon Nov 5 2018 Remi Collet - 2.8.47-1 - update to 2.8.47 * Thu Oct 18 2018 Remi Collet - 2.8.46-2 - ignore doctrine/data-fixturesversion * Mon Oct 1 2018 Remi Collet - 2.8.46-1 - update to 2.8.46 * Tue Aug 28 2018 Remi Collet - 2.8.45-1 - update to 2.8.45 - debug and ldap: add missing dependency on common * Wed Aug 1 2018 Shawn Iwinski - 2.8.44-1 - Update to 2.8.44 (CVE-2018-14773 / CVE-2018-14774) * Fri Jul 13 2018 Fedora Release Engineering - 2.8.42-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Mon Jun 25 2018 Shawn Iwinski - 2.8.42-1 - Update to 2.8.42 * Mon May 28 2018 Remi Collet - 2.8.41-1 - update to 2.8.41 * Thu May 24 2018 Remi Collet - 2.8.40-1 - update to 2.8.40 * Fri May 4 2018 Remi Collet - 2.8.39-1 - update to 2.8.39 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-3ee6a7adf2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-0ef4149687 2019-04-27 21:22:10.074172 --------------------------------------------------------------------------------Name : php-symfony Product : Fedora 30 Version : 2.8.51 Release : 1.fc30 URL : https://symfony.com Summary : PHP framework for web projects Description : PHP framework for web projects --------------------------------------------------------------------------------Update Information: **Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security #cve-2019-10911 [Security] Add a separator in the remember me cookie hash (pborreli) * security #cve-2019-10913 [HttpFoundation] reject invalid method override (nicolas-grekas) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 18 2019 Remi Collet - 2.8.51-1 - update to 2.8.51 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-0ef4149687' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for obs-service-source_validator ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1659-1 Rating: important References: #967265 #967610 Cross-References: CVE-2016-4007 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: obs-service-source_validator was updated to fix one security issue. This security issue was fixed: - CVE-2016-4007: Several maintained source services are vulnerable to code/paramter injection (bsc#967265). This non-security issue was fixed: - bsc#967610: Several occurrences of uninitialized value. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2016-758=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (noarch): obs-service-source_validator-0.6+git20160531.fbfe336-9.1 References: https://www.suse.com/security/cve/CVE-2016-4007.html https://bugzilla.suse.com/967265 https://bugzilla.suse.com/967610 -- . Important revision for obs-service_source_validator mitigates potential code execution vulnerabilities in openSUSE environments.. openSUSE Update, Code Injection, Service Validator, Security Fix. . Severity: Important. LinuxSecurity.com Team
Moderate: krb5 security update. Date: Thu, 13 Jun 2013 21:45:23 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Bonnie King Subject: Security ERRATA Moderate: krb5 on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: krb5 security update Advisory ID: SLSA-2013:0942-1 Issue Date: 2013-06-12 CVE Numbers: CVE-2002-2443 -- It was found that kadmind's kpasswd service did not perform any validation on incoming network packets, causing it to reply to all requests. A remote attacker could use this flaw to send spoofed packets to a kpasswd service that appear to come from kadmind on a different server, causing the services to keep replying packets to each other, consuming network bandwidth and CPU. (CVE-2002-2443) After installing the updated packages, the krb5kdc and kadmind daemons will be restarted automatically. -- SL5 x86_64 krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-debuginfo-1.6.1-70.el5_9.2.x86_64.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.x86_64.rpm krb5-workstation-1.6.1-70.el5_9.2.x86_64.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-ldap-1.6.1-70.el5_9.2.x86_64.rpm i386 krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-workstation-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-server-1.6.1-70.el5_9.2.i386.rpm krb5-server-ldap-1.6.1-70.el5_9.2.i386.rpm SL6 x86_64 krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.x86_64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.x86_64.rpm krb5-workstation-1.10.3-10.el6_4.3.x86_64.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.x86_64.rpm i386 krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.i686.rpm krb5-workstation-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-server-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm - Scientific Linux Development Team . A significant security patch for krb5 in Scientific Linux SL5.x and SL6.x has been issued to mitigate risks associated with possible network vulnerabilities.. krb5 Security Update, Scientific Linux, Network Attack, Security Advisory, Moderate Severity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.