CVE-2012-2667
published 2012-06-07CVE-2012-2667: Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.35%
68.3th percentile
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sensiolabs | symfony | <= 1.4.17 | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version [fedora-all]
bugzilla·2012-06-04·CVSS 4.3
CVE-2012-2667 [MEDIUM] CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version [fedora-all]
CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.
Bugzilla
CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version [epel-6]
bugzilla·2012-06-04·CVSS 4.3
CVE-2012-2667 [MEDIUM] CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version [epel-6]
CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
Bugzilla
CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version
bugzilla·2012-06-04·CVSS 4.3
CVE-2012-2667 [MEDIUM] CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version
CVE-2012-2667 php-symfony-symfony: Session fixation flaw corrected in upstream 1.4.18 version
A session fixation flaw was found in the way Symfony, an open-source PHP web applications development framework, performed removal of user credential, adding several user credentials at once and 'user authenticated' settings change by regenerating session ID. A remote attacker could provide a specially-crafted URL, that when visited by a valid Symfony application user (victim) could lead to unauthorized access to the victim's user account.
References:
[1] https://bugs.gentoo.org/show_bug.cgi?id=418427
[2] http://symfony.com/blog/security-release-symfony-1-4-18-released
[3] http://trac.symfony-project.org/browser/tags/RELEASE_1_4_18/CHANGELOG
Upstream patch:
[4] http://trac.symfony-project.org/c
http://secunia.com/advisories/49312http://symfony.com/blog/security-release-symfony-1-4-18-releasedhttp://trac.symfony-project.org/browser/tags/RELEASE_1_4_18/CHANGELOGhttp://www.openwall.com/lists/oss-security/2012/06/04/1http://www.openwall.com/lists/oss-security/2012/06/05/2http://www.securityfocus.com/bid/53776https://exchange.xforce.ibmcloud.com/vulnerabilities/76027http://secunia.com/advisories/49312http://symfony.com/blog/security-release-symfony-1-4-18-releasedhttp://trac.symfony-project.org/browser/tags/RELEASE_1_4_18/CHANGELOGhttp://www.openwall.com/lists/oss-security/2012/06/04/1http://www.openwall.com/lists/oss-security/2012/06/05/2http://www.securityfocus.com/bid/53776https://exchange.xforce.ibmcloud.com/vulnerabilities/76027
2012-06-07
Published