Skip to content

Conversation

@adrienperonnet
Copy link
Contributor

guessFromFileBinary may also be impacted by cve-2019-18888 where
the provided file paths were not being properly escaped before being used.

This PR backports the fix from commit symfony/symfony@691486e to make sure the issue is not exploitable.

Copy link
Contributor

@alquerci alquerci left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hello @adrienperonnet,

Thank you for this security fix, but there is one patch to do.

See the line comment.

👎

Copy link
Contributor

@alquerci alquerci left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

cc @thePanz

@j0k3r j0k3r merged commit 444fb9c into FriendsOfSymfony1:master Apr 3, 2020
j0k3r added a commit that referenced this pull request Apr 3, 2020
j0k3r added a commit that referenced this pull request Apr 3, 2020
terdia pushed a commit to amboss-mededu/php-symfony1 that referenced this pull request May 28, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants