SB2015040204 - Fedora 22 update for php-symfony
Published: April 2, 2015 Updated: April 24, 2025
Security Bulletin ID
SB2015040204
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Code Injection (CVE-ID: CVE-2015-2308)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.
Remediation
Install update from vendor's website.