VDB
Sign up
MEDIUM

GHSA-cr49-fx2v-9p57

Symfony Denial of Service Via Long Password Hashing

Quick fix

GHSA-cr49-fx2v-9p57 — symfony/symfony: upgrade to the fixed version with the command below.

composer require symfony/symfony:^2.0.25

Details

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/symfony
Introduced in: 2.0.0Fixed in: 2.0.25
Fixcomposer require symfony/symfony:^2.0.25
Packagist/symfony/symfony
Introduced in: 2.1.0Fixed in: 2.1.13
Fixcomposer require symfony/symfony:^2.1.13
Packagist/symfony/symfony
Introduced in: 2.2.0Fixed in: 2.2.9
Fixcomposer require symfony/symfony:^2.2.9
Packagist/symfony/symfony
Introduced in: 2.3.0Fixed in: 2.3.6
Fixcomposer require symfony/symfony:^2.3.6
Packagist/symfony/polyfill
Introduced in: 1.0.0Fixed in: 1.10.0
Fixcomposer require symfony/polyfill:^1.10.0
Packagist/symfony/security
Introduced in: 2.0.0Fixed in: 2.0.25
Fixcomposer require symfony/security:^2.0.25
Packagist/symfony/security
Introduced in: 2.1.0Fixed in: 2.1.13
Fixcomposer require symfony/security:^2.1.13
Packagist/symfony/security
Introduced in: 2.2.0Fixed in: 2.2.9
Fixcomposer require symfony/security:^2.2.9
Packagist/symfony/security
Introduced in: 2.3.0Fixed in: 2.3.6
Fixcomposer require symfony/security:^2.3.6

References