Release date:
Updated on:
Affected Systems:
Symfony <2.0.20
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-6431
Symfony is a PHP framework based on the MVC Architecture. It is a free software released with the MIT License.
The Routing and Security components of Symfony 2.0.x process the encoded URLs differently. Attackers can bypass the internal URI restrictions through dual-encoded URLs.
<* Source: vendor
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-6431
Http://symfony.com/blog/security-release-symfony-2-0-20-and-2-1-5-released
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Symfony
-------
Symfony has released a Security Bulletin (security-release-symfony-2-0-20-and-2-1-5-released) and corresponding patches for this:
Security-release-symfony-2-0-20-and-2-1-5-released: Security release: Symfony 2.0.20 and 2.1.5 released
Link: http://symfony.com/blog/security-release-symfony-2-0-20-and-2-1-5-released
Patch download: https://github.com/symfony/symfony/commit/55014a6841bec50046e8329a4835c160ac31a496