CVE-2013-5958Memory Allocation with Excessive Size Value in Polyfill

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 27
Latest updateMay 17

Description

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Packagistsymfony/security2.0.02.0.25+3
Packagistsymfony/symfony2.0.02.0.25+3
Packagistsymfony/polyfill1.0.01.10.0
NVDsensiolabs/symfony53 versions+52

🔴Vulnerability Details

3
GHSA
Symfony Denial of Service Via Long Password Hashing2022-05-17
OSV
Symfony Denial of Service Via Long Password Hashing2022-05-17
CVEList
CVE-2013-5958: The Security component in Symfony 22014-12-27

📋Vendor Advisories

2
Cisco
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities2013-01-30
Debian
CVE-2013-5958: symfony - The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2....2013
CVE-2013-5958 — Symfony Polyfill vulnerability | cvebase