Fedora 24 : php-doctrine-orm (2016-f0c8b7b115)

high Nessus Plugin ID 92447


The remote Fedora host is missing a security update.


## v2.4.8

### Security

- CVE-2015-5723 php-doctrine-orm filesystem permission issues

- https://access.redhat.com/security/cve/CVE-2015-5723

- http://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html

### Bug

- [DDC-3310] - [GH-1138] Join column index names

- [DDC-3343] - `PersistentCollection::removeElement` schedules an entity for deletion when relationship is EXTRA_LAZY, with `orphanRemoval` false.

- [DDC-3464] - [GH-1231] Backport 'Merge pull request #1098 from encoder32/DDC-1590' to 2.4 branch

- [DDC-3482] - [GH-1242] Attempting to lock a proxy object fails as UOW doesn't init proxy first

- [DDC-3493] - New (PHP 5.5) 'class' keyword - wrong parsing by EntityGenerator

- [DDC-3494] - [GH-1250] Test case for 'class' keyword

- [DDC-3500] - [GH-1254] Fix applying ON/WITH conditions to first join in Class Table Inheritance

- [DDC-3502] - [GH-1256] DDC-3493 - fixed EntityGenerator parsing for php 5.5 '::class' syntax

- [DDC-3518] - [GH-1266] [2.4] Fix schema generation in the test suite

- [DDC-3537] - [GH-1282] Hotfix/#1169 extra lazy one to many should not delete referenced entities (backport to 2.4)

- [DDC-3551] - [GH-1294] Avoid Connection error when calling ClassMetadataFactor::getAllMetadata()

- [DDC-3560] - [GH-1300] [2.4] #1169 DDC-3343 one-to-omany persister deletes only on EXTRA_LAZY plus orphanRemoval

- [DDC-3608] - [GH-1327] Properly generate default value from yml & xml mapping

- [DDC-3619] - spl_object_hash collision

- [DDC-3624] - [GH-1338] [DDC-3619] Update identityMap when entity gets managed again

- [DDC-3643] - [GH-1352] fix EntityGenerator RegenerateEntityIfExists

### Improvement

- [DDC-3530] - [GH-1276] travis: run coverage just once

Update the affected php-doctrine-orm package.

See Also


Plugin Details

Severity: High

ID: 92447

File Name: fedora_2016-f0c8b7b115.nasl

Version: 2.5

Type: local

Agent: unix

Published: 7/20/2016

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent

Risk Information


Risk Factor: Medium

Score: 5.9


Risk Factor: High

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C


Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php-doctrine-orm, cpe:/o:fedoraproject:fedora:24

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 7/19/2016

Vulnerability Publication Date: 6/7/2016

Reference Information

CVE: CVE-2015-5723