CVE-2012-5574: Medium severity symfony vulnerability
An information disclosure flaw was found in the way Symfony, a open-source PHP web framework, sanitized certain HTTP POST request values. A remote attacker could use this flaw to obtain (unauthorized) read access to arbitrary system files, readable with the privileges of the web server process.
References: [1] http://symfony.com/blog/security-release-symfony-1-4-20-released [2] https://bugs.gentoo.org/showbug.cgi?id=444696
Relevant upstream patch: [3] http://trac.symfony-project.org/changeset/33598
Other sources
lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5574?
CVE-2012-5574 is considered an information disclosure vulnerability.
How do I fix CVE-2012-5574?
To fix CVE-2012-5574, upgrade to Symfony version 1.4.20 or later.
What types of systems are affected by CVE-2012-5574?
CVE-2012-5574 affects specific versions of the Symfony PHP web framework.
Can CVE-2012-5574 lead to unauthorized file access?
Yes, CVE-2012-5574 allows remote attackers to gain unauthorized read access to system files.
Which versions of Symfony are vulnerable to CVE-2012-5574?
Symfony versions up to and including 1.4.19 are vulnerable to CVE-2012-5574.