DEBIAN-CVE-2024-50343

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2024-50343
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50343.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-50343
Upstream
Published
2024-11-06T21:15:06Z
Modified
2025-09-25T04:18:45.774066Z
Summary
[none]
Details

symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a Validator configured with a regular expression using the $ metacharacters, with an input ending with \n. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the D regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References

Affected packages

Debian:11 / symfony

Package

Name
symfony
Purl
pkg:deb/debian/symfony?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.19+dfsg-2+deb11u7

Affected versions

4.*

4.4.19+dfsg-2
4.4.19+dfsg-2+deb11u1
4.4.19+dfsg-2+deb11u2
4.4.19+dfsg-2+deb11u3
4.4.19+dfsg-2+deb11u4
4.4.19+dfsg-2+deb11u5
4.4.19+dfsg-2+deb11u6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / symfony

Package

Name
symfony
Purl
pkg:deb/debian/symfony?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.23+dfsg-1+deb12u3

Affected versions

5.*

5.4.23+dfsg-1
5.4.23+dfsg-1+deb12u1
5.4.23+dfsg-1+deb12u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / symfony

Package

Name
symfony
Purl
pkg:deb/debian/symfony?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.11+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / symfony

Package

Name
symfony
Purl
pkg:deb/debian/symfony?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.11+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}