CVE-2013-1397: Code Injection
Ability to enable/disable object support in YAML parsing and dumping
Other sources
Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1397?
CVE-2013-1397 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2013-1397?
To fix CVE-2013-1397, update Symfony to version 2.0.22, 2.1.7, or 2.2.0-BETA2 or later.
Which versions are affected by CVE-2013-1397?
CVE-2013-1397 affects Symfony versions 2.0.x prior to 2.0.22, 2.1.x prior to 2.1.7, and 2.2.x before 2.2.0-BETA2.
What type of attack does CVE-2013-1397 enable?
CVE-2013-1397 enables remote attackers to execute arbitrary PHP code via a serialized PHP object.
Is CVE-2013-1397 a historical vulnerability?
Yes, CVE-2013-1397 is a historical vulnerability that was disclosed in 2013 and has been patched in supported versions of Symfony.