Name | CVE-2018-11386 |
Description | An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-4262-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
symfony (PTS) | jessie, jessie (lts) | 2.3.21+dfsg-4+deb8u6 | fixed |
stretch (security) | 2.8.7+dfsg-1.3+deb9u3 | fixed | |
stretch (lts), stretch | 2.8.7+dfsg-1.3+deb9u5 | fixed | |
buster (security), buster, buster (lts) | 3.4.22+dfsg-2+deb10u3 | fixed | |
bullseye | 4.4.19+dfsg-2+deb11u6 | fixed | |
bookworm | 5.4.23+dfsg-1+deb12u2 | fixed | |
bookworm (security) | 5.4.23+dfsg-1+deb12u4 | fixed | |
sid, trixie | 6.4.16+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
symfony | source | jessie | (not affected) | |||
symfony | source | stretch | 2.8.7+dfsg-1.3+deb9u1 | DSA-4262-1 | ||
symfony | source | (unstable) | 3.4.12+dfsg-1 |
[jessie] - symfony <not-affected> (vulnerable code no present, no rollback mechanism in this version)
https://symfony.com/blog/cve-2018-11386-denial-of-service-when-using-pdosessionhandler