Vulnerability Bulletins

DSA-3276 symfony - security update

   
Affected software Debian
 
Jakub Zalas discovered that Symfony, a framework to create websites andweb applications, was vulnerable to restriction bypass. It wasaffecting applications with ESI or SSI support enabled, that use theFragmentListener. A malicious user could call any controller via the/_fragment path by providing an invalid hash in the URL (or removingit), bypassing URL signing and security rules.

More info:

https://www.debian.org/security/2015/dsa-3276