[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3402-1 symfony -- symfony

ID: oval:org.secpod.oval:def:602285Date: (C)2015-12-02   (M)2022-09-22
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in symfony, a framework to create websites and web applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8124 The RedTeam Pentesting GmbH team discovered a session fixation vulnerability within the "Remember Me" login feature, allowing an attacker to impersonate the victim towards the web application if the session id value was previously known to the attacker. CVE-2015-8125 Several potential remote timing attack vulnerabilities were discovered in classes from the Symfony Security component and in the legacy CSRF implementation from the Symfony Form component.

Platform:
Debian 8.x
Product:
php-symfony
Reference:
DSA-3402-1
CVE-2015-8124
CVE-2015-8125
CVE    2
CVE-2015-8124
CVE-2015-8125
CPE    2
cpe:/a:symfony:php-symfony
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies