CVE-2015-4050

NameCVE-2015-4050
DescriptionFragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3276-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
symfony (PTS)jessie (security), jessie2.3.21+dfsg-4+deb8u3fixed
buster, sid, stretch2.8.7+dfsg-1.3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
symfonysource(unstable)2.7.0~beta2+dfsg-2medium
symfonysourcejessie2.3.21+dfsg-4+deb8u1mediumDSA-3276-1

Notes

https://github.com/fabpot/symfony/commit/d320d27699abcea12479cf608908fa91bcc133d4
http://symfony.com/blog/cve-2015-4050-esi-unauthorized-access

Search for package or bug name: Reporting problems