CVE-2019-18888

NameCVE-2019-18888
DescriptionAn issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1999-1, DSA-4573-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
symfony (PTS)jessie2.3.21+dfsg-4+deb8u3vulnerable
jessie (security)2.3.21+dfsg-4+deb8u6fixed
stretch2.8.7+dfsg-1.3+deb9u2vulnerable
stretch (security)2.8.7+dfsg-1.3+deb9u3fixed
buster3.4.22+dfsg-2vulnerable
buster (security)3.4.22+dfsg-2+deb10u1fixed
bullseye, sid4.3.8+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
symfonysource(unstable)4.3.8+dfsg-1
symfonysourcebuster3.4.22+dfsg-2+deb10u1DSA-4573-1
symfonysourcejessie2.3.21+dfsg-4+deb8u6DLA-1999-1
symfonysourcestretch2.8.7+dfsg-1.3+deb9u3DSA-4573-1

Notes

https://symfony.com/blog/cve-2019-18888-prevent-argument-injection-in-a-mimetypeguesser
https://github.com/symfony/symfony/commit/691486e43ce0e4893cd703e221bafc10a871f365
https://github.com/symfony/symfony/commit/77ddabf2e785ea85860d2720cc86f7c5d8967ed5

Search for package or bug name: Reporting problems