News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Symfony Blog:
symfony 1.0.5 released (security fix)
June 28, 2007 @ 10:31:00

The Symfony project has released the latest version of their framework - Symfony 1.0.5 - largely a security fix release to help head off some issues that came up with the phpmailer utility.

I've just released symfony 1.0.5. If you use the symfony built-in phpmailer (and you do if you use the ->sendMail() method in your actions), you must upgrade to this release or apply the following patch: http://trac.symfony-project.com/trac/changeset/4380?format=diff&new=4380. PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/

The easiest way to correct the issue is to just apply the patch to your current installation, but since there are other fixes included in the new version, you might opt for the update anyway.

0 comments voice your opinion now!
symfony framework release security phpmailer vulnerability symfony framework release security phpmailer vulnerability


blog comments powered by Disqus

Similar Posts

Christian Wenz's Blog: SANS Top-20 Internet Security Attack Targets (2006 Annual Update)

Anna Filina's Blog: Symfony - subfolders for partials

ThisLab: Notes on Choosing a PHP Framework: A Quick Comparison of CodeIgniter and Kohana

Dave Dash's Blog: Using sfDoctrine to match allowed email domains

PHPClasses.org: PHPNG Dramatic Speedup Features Coming in PHP 6 Release


Community Events

Don't see your event here?
Let us know!


api series language list conference framework application community composer opinion project example php7 introduction symfony part2 podcast laravel interview yii2

All content copyright, 2015 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework