Debian DLA-3664-1 : symfony - LTS security update

medium Nessus Plugin ID 186245

Synopsis

The remote Debian host is missing a security-related update.

Description

The remote Debian 10 host has packages installed that are affected by a vulnerability as referenced in the dla-3664 advisory.

- Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters. (CVE-2023-46734)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade the symfony packages.

For Debian 10 buster, this problem has been fixed in version 3.4.22+dfsg-2+deb10u3.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1055774

https://security-tracker.debian.org/tracker/source-package/symfony

https://www.debian.org/lts/security/2023/dla-3664

https://security-tracker.debian.org/tracker/CVE-2023-46734

https://packages.debian.org/source/buster/symfony

Plugin Details

Severity: Medium

ID: 186245

File Name: debian_DLA-3664.nasl

Version: 1.0

Type: local

Agent: unix

Published: 11/24/2023

Updated: 11/24/2023

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2023-46734

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:php-symfony-http-foundation, p-cpe:/a:debian:debian_linux:php-symfony-http-kernel, p-cpe:/a:debian:debian_linux:php-symfony-security-guard, p-cpe:/a:debian:debian_linux:php-symfony-workflow, p-cpe:/a:debian:debian_linux:php-symfony-css-selector, p-cpe:/a:debian:debian_linux:php-symfony-process, p-cpe:/a:debian:debian_linux:php-symfony-browser-kit, p-cpe:/a:debian:debian_linux:php-symfony-class-loader, p-cpe:/a:debian:debian_linux:php-symfony-doctrine-bridge, p-cpe:/a:debian:debian_linux:php-symfony-phpunit-bridge, p-cpe:/a:debian:debian_linux:php-symfony-web-link, p-cpe:/a:debian:debian_linux:php-symfony-web-server-bundle, p-cpe:/a:debian:debian_linux:php-symfony-expression-language, p-cpe:/a:debian:debian_linux:php-symfony-options-resolver, p-cpe:/a:debian:debian_linux:php-symfony-property-info, p-cpe:/a:debian:debian_linux:php-symfony-security, p-cpe:/a:debian:debian_linux:php-symfony-twig-bundle, p-cpe:/a:debian:debian_linux:php-symfony-debug-bundle, p-cpe:/a:debian:debian_linux:php-symfony-validator, cpe:/o:debian:debian_linux:10.0, p-cpe:/a:debian:debian_linux:php-symfony-event-dispatcher, p-cpe:/a:debian:debian_linux:php-symfony-filesystem, p-cpe:/a:debian:debian_linux:php-symfony-inflector, p-cpe:/a:debian:debian_linux:php-symfony-security-http, p-cpe:/a:debian:debian_linux:php-symfony-var-dumper, p-cpe:/a:debian:debian_linux:php-symfony-debug, p-cpe:/a:debian:debian_linux:php-symfony-intl, p-cpe:/a:debian:debian_linux:php-symfony-proxy-manager-bridge, p-cpe:/a:debian:debian_linux:php-symfony-twig-bridge, p-cpe:/a:debian:debian_linux:php-symfony-web-profiler-bundle, p-cpe:/a:debian:debian_linux:php-symfony-dotenv, p-cpe:/a:debian:debian_linux:php-symfony-lock, p-cpe:/a:debian:debian_linux:php-symfony-console, p-cpe:/a:debian:debian_linux:php-symfony-finder, p-cpe:/a:debian:debian_linux:php-symfony-serializer, p-cpe:/a:debian:debian_linux:php-symfony-ldap, p-cpe:/a:debian:debian_linux:php-symfony-security-bundle, p-cpe:/a:debian:debian_linux:php-symfony-security-csrf, p-cpe:/a:debian:debian_linux:php-symfony-security-core, p-cpe:/a:debian:debian_linux:php-symfony, p-cpe:/a:debian:debian_linux:php-symfony-config, p-cpe:/a:debian:debian_linux:php-symfony-dom-crawler, p-cpe:/a:debian:debian_linux:php-symfony-translation, p-cpe:/a:debian:debian_linux:php-symfony-asset, p-cpe:/a:debian:debian_linux:php-symfony-framework-bundle, p-cpe:/a:debian:debian_linux:php-symfony-property-access, p-cpe:/a:debian:debian_linux:php-symfony-cache, p-cpe:/a:debian:debian_linux:php-symfony-dependency-injection, p-cpe:/a:debian:debian_linux:php-symfony-form, p-cpe:/a:debian:debian_linux:php-symfony-monolog-bridge, p-cpe:/a:debian:debian_linux:php-symfony-routing, p-cpe:/a:debian:debian_linux:php-symfony-stopwatch, p-cpe:/a:debian:debian_linux:php-symfony-templating, p-cpe:/a:debian:debian_linux:php-symfony-yaml

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 11/24/2023

Vulnerability Publication Date: 11/10/2023

Reference Information

CVE: CVE-2023-46734