First published: Fri May 25 2018(Updated: )
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.0.0<2.1.0>=2.1.0<2.2.0>=2.2.0<2.3.0>=2.3.0<2.4.0>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.7.48>=2.8.0<2.8.41>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.3.17>=3.4.0<3.4.11>=4.0.0<4.0.11 | |
composer/symfony/http-foundation | >=2.0.0<2.1.0>=2.1.0<2.2.0>=2.2.0<2.3.0>=2.3.0<2.4.0>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.7.48>=2.8.0<2.8.41>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.3.17>=3.4.0<3.4.11>=4.0.0<4.0.11 | |
composer/symfony/symfony | >=4.0.0<4.0.11 | 4.0.11 |
composer/symfony/symfony | >=3.4.0<3.4.11 | 3.4.11 |
composer/symfony/symfony | >=3.3.0<3.3.17 | 3.3.17 |
composer/symfony/symfony | >=2.8.0<2.8.41 | 2.8.41 |
composer/symfony/symfony | >=2.7.0<2.7.48 | 2.7.48 |
SensioLabs Symfony | >=2.7.0<2.7.48 | |
SensioLabs Symfony | >=2.8.0<2.8.41 | |
SensioLabs Symfony | >=3.3.0<3.3.17 | |
SensioLabs Symfony | >=3.4.0<3.4.11 | |
SensioLabs Symfony | >=4.0.0<4.0.11 | |
Debian Debian Linux | =9.0 | |
debian/symfony | 3.4.22+dfsg-2+deb10u1 3.4.22+dfsg-2+deb10u2 4.4.19+dfsg-2+deb11u3 5.4.23+dfsg-1 5.4.29+dfsg-1 5.4.30+dfsg-1 | |
composer/symfony/http-foundation | >=4.0.0<4.0.11 | 4.0.11 |
composer/symfony/http-foundation | >=3.4.0<3.4.11 | 3.4.11 |
composer/symfony/http-foundation | >=3.3.0<3.3.17 | 3.3.17 |
composer/symfony/http-foundation | >=2.8.0<2.8.41 | 2.8.41 |
composer/symfony/http-foundation | >=2.7.0<2.7.48 | 2.7.48 |
>=2.7.0<2.7.48 | ||
>=2.8.0<2.8.41 | ||
>=3.3.0<3.3.17 | ||
>=3.4.0<3.4.11 | ||
>=4.0.0<4.0.11 | ||
=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11386 is medium, with a severity value of 5.9.
CVE-2018-11386 affects Symfony versions 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11.
The vulnerability in CVE-2018-11386 is a denial of service vulnerability when using PDOSessionHandler in Symfony.
To fix CVE-2018-11386, update Symfony to versions 2.7.48, 2.8.41, 3.3.17, 3.4.11, or 4.0.11.
You can find more information about CVE-2018-11386 at the following links: [Symfony](https://symfony.com/cve-2018-11386), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-11386), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4XNBMFW33H47O5TZGA7JYCVLDBCXAJV/)