Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-5958

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2013-5958
Last Modified 29 Dec 2014 05:55:14
Published 27 Dec 2014 01:59:01
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2013-5958

Summary

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

Vulnerable Systems

Application

  • Sensiolabs Symfony 2.0.0

  • Sensiolabs Symfony 2.0.1

  • Sensiolabs Symfony 2.0.10

  • Sensiolabs Symfony 2.0.11

  • Sensiolabs Symfony 2.0.12

  • Sensiolabs Symfony 2.0.13

  • Sensiolabs Symfony 2.0.14

  • Sensiolabs Symfony 2.0.15

  • Sensiolabs Symfony 2.0.16

  • Sensiolabs Symfony 2.0.17

  • Sensiolabs Symfony 2.0.18

  • Sensiolabs Symfony 2.0.19

  • Sensiolabs Symfony 2.0.2

  • Sensiolabs Symfony 2.0.20

  • Sensiolabs Symfony 2.0.21

  • Sensiolabs Symfony 2.0.22

  • Sensiolabs Symfony 2.0.23

  • Sensiolabs Symfony 2.0.24

  • Sensiolabs Symfony 2.0.3

  • Sensiolabs Symfony 2.0.4

  • Sensiolabs Symfony 2.0.5

  • Sensiolabs Symfony 2.0.6

  • Sensiolabs Symfony 2.0.7

  • Sensiolabs Symfony 2.0.8

  • Sensiolabs Symfony 2.0.9

  • Sensiolabs Symfony 2.1.0

  • Sensiolabs Symfony 2.1.1

  • Sensiolabs Symfony 2.1.10

  • Sensiolabs Symfony 2.1.11

  • Sensiolabs Symfony 2.1.12

  • Sensiolabs Symfony 2.1.2

  • Sensiolabs Symfony 2.1.3

  • Sensiolabs Symfony 2.1.4

  • Sensiolabs Symfony 2.1.5

  • Sensiolabs Symfony 2.1.6

  • Sensiolabs Symfony 2.1.7

  • Sensiolabs Symfony 2.1.8

  • Sensiolabs Symfony 2.1.9

  • Sensiolabs Symfony 2.2

  • Sensiolabs Symfony 2.2.0

  • Sensiolabs Symfony 2.2.1

  • Sensiolabs Symfony 2.2.2

  • Sensiolabs Symfony 2.2.3

  • Sensiolabs Symfony 2.2.4

  • Sensiolabs Symfony 2.2.5

  • Sensiolabs Symfony 2.2.6

  • Sensiolabs Symfony 2.2.8

  • Sensiolabs Symfony 2.3.0

  • Sensiolabs Symfony 2.3.1

  • Sensiolabs Symfony 2.3.2

  • Sensiolabs Symfony 2.3.3

  • Sensiolabs Symfony 2.3.4

  • Sensiolabs Symfony 2.3.5


References

CONFIRM - http://symfony.com/blog/security-releases-cve-2013-5958-symfony-2-0-25-2-1-13-2-2-9-and-2-3-6-released


Last Updated: 27 May 2016 11:07:22