Bug 926177 (CVE-2015-2308) - VUL-0: CVE-2015-2308, CVE-2015-2309: symfony: Esi Code Injection, Unsafe methods in the Request class
Summary: VUL-0: CVE-2015-2308, CVE-2015-2309: symfony: Esi Code Injection, Unsafe meth...
Status: RESOLVED FIXED
Alias: CVE-2015-2308
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: E-mail List
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-04-07 09:37 UTC by Andreas Stieger
Modified: 2023-08-07 02:41 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-04-07 09:37:51 UTC
Reported against server:php:applications. Not in openSUSE or SLE.

We got some sketchy details about vulnerabilities in php symfony, see references below.

server:php:applications packages 1.0.11 which is old unsupported. The issues may not affect it.

Current LTS is 2.3.27, current stable is 2.6.6.

This is just a ping to see if this package is still maintained? If so could it be updated?

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2308
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-2308.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2308

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2309
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-2309.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2309
Comment 1 Swamp Workflow Management 2015-04-07 22:00:23 UTC
bugbot adjusting priority
Comment 2 Chenzi Cao 2023-08-07 02:41:34 UTC
This is a quite old bug, can not set needinfo to the bug reporter any longer. So close it now, but please feel free to reopen it whenever necessary, thanks.