[ubuntu/focal-proposed] symfony 4.3.8+dfsg-1 (Accepted)

Gianfranco Costamagna costamagnagianfranco at yahoo.it
Sun Nov 24 08:42:04 UTC 2019


symfony (4.3.8+dfsg-1) unstable; urgency=medium

  [ Christophe Coevoet ]
  * Use constant time comparison in UriSigner [CVE-2019-18887]

  [ Nicolas Grekas ]
  * [Cache] forbid serializing AbstractAdapter and TagAwareAdapter instances
    [CVE-2019-18889]
  * [VarExporter] fix exporting some strings [CVE-2019-11325]
  * [HttpFoundation] fix guessing mime-types of files with leading dash
    [CVE-2019-18888]
  * [Mime] fix guessing mime-types of files with leading dash [CVE-2019-18888]
  * [Security\Core] throw AccessDeniedException when switch user fails
    [CVE-2019-18886]

  [ Fabien Potencier ]
  * updated VERSION for 4.3.8

  [ David Prévot ]
  * Track stable version for now
  * Update homemade overrides
  * Exclude whole directory

Date: 2019-11-13 22:42:16.067571+00:00
Signed-By: Gianfranco Costamagna <costamagnagianfranco at yahoo.it>
https://launchpad.net/ubuntu/+source/symfony/4.3.8+dfsg-1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list