News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Symfony Blog:
symfony 1.0.5 released (security fix)
June 28, 2007 @ 10:31:00

The Symfony project has released the latest version of their framework - Symfony 1.0.5 - largely a security fix release to help head off some issues that came up with the phpmailer utility.

I've just released symfony 1.0.5. If you use the symfony built-in phpmailer (and you do if you use the ->sendMail() method in your actions), you must upgrade to this release or apply the following patch: http://trac.symfony-project.com/trac/changeset/4380?format=diff&new=4380. PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/

The easiest way to correct the issue is to just apply the patch to your current installation, but since there are other fixes included in the new version, you might opt for the update anyway.

0 comments voice your opinion now!
symfony framework release security phpmailer vulnerability symfony framework release security phpmailer vulnerability



Similar Posts

SitePoint PHP Blog: Rasmus Lerdorf - Web 2.0\'s John Wayne

Wez Furlong\'s Blog: Programming PHP (Second Edition)

PHPImpact Blog: TDD with Symfony: The first test always fails

Chris Hartjes' Blog: 10 Days Later - Early Impressions of CakePHP vs. CodeIgniter

KillerSoft.com: SimpleTest 1.0.0 on Pearified.com


Community Events







Don't see your event here?
Let us know!


example package PEAR zendframework book zend PHP5 job framework application cakephp developer releases security code ajax conference database release mysql

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework