-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 09 Nov 2024 10:22:58 +0100 Source: symfony Architecture: source Version: 5.4.23+dfsg-1+deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: Debian PHP PEAR Maintainers Changed-By: David Prévot Changes: symfony (5.4.23+dfsg-1+deb12u3) bookworm-security; urgency=medium . * Backport security fixes from Symfony 5.4.46 - [Validator] Add D regex modifier in relevant validators [CVE-2024-50343] - Do not read from argv on non-CLI SAPIs [CVE-2024-50340] - [HttpClient] Filter private IPs before connecting when Host == IP [CVE-2024-50342] - [HttpFoundation] Reject URIs that contain invalid characters [CVE-2024-50345] * Backport fixes to test suite Checksums-Sha1: d6378734c2a11b6c50330c5bdc80feb622d3f355 13233 symfony_5.4.23+dfsg-1+deb12u3.dsc 407992787c0191683ccd4a12cbcc7a8cfba81d6f 4925068 symfony_5.4.23+dfsg.orig.tar.xz 017ff631bc4fc41a5a6a671e792114947ee4be7c 73628 symfony_5.4.23+dfsg-1+deb12u3.debian.tar.xz 197f4fd86c54750596a1ba96b263997a6db9e486 57205 symfony_5.4.23+dfsg-1+deb12u3_amd64.buildinfo Checksums-Sha256: e6f6242b013d0c4a5703903aad4888bc816387003eaf48297b92256e80bc0c0b 13233 symfony_5.4.23+dfsg-1+deb12u3.dsc 5befdfa2f0b6c313df50f4683694b7761a6f9a6b6d540bdc3fa99c953fc22037 4925068 symfony_5.4.23+dfsg.orig.tar.xz 65a9162c291122c24d20b149ff1678b1c3eaea4a02ce7dfff5208e8b4910b41a 73628 symfony_5.4.23+dfsg-1+deb12u3.debian.tar.xz f13e2ea7e2891ba5e74b5be3680659ca6f9dbc498efe4f9c0ef684a8a15b88be 57205 symfony_5.4.23+dfsg-1+deb12u3_amd64.buildinfo Files: 2514f2ffe0e506050c081aafb54e2a5e 13233 php optional symfony_5.4.23+dfsg-1+deb12u3.dsc 3eeb8496264f56166d1a97ebb70de052 4925068 php optional symfony_5.4.23+dfsg.orig.tar.xz 51ba88a9b24153c60a150ef7342e752a 73628 php optional symfony_5.4.23+dfsg-1+deb12u3.debian.tar.xz 1477e88c920816d9e1a2d6aed0934659 57205 php optional symfony_5.4.23+dfsg-1+deb12u3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQFGBAEBCAAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmcxu9gSHHRhZmZpdEBk ZWJpYW4ub3JnAAoJEAWMHPlE9r08bsAH+wa6O/+IWm1bP6epE7oo4ah0ZNa1TJ7F N2adX2L0geRPmQxum323Cqau7ArarAegdxUPJaXD8w6xN4CBWIAtMQ+Rdmx71kVK PTds9fE0kIp4uXJtfelCv7HDC9/ifej43ovCNQNyxuxu1XtmWvgITdiuXtU0vXcb gloCAgZ01Zuao13N/b9TRBDalhqtS7HecIuQGO85DnuaIZnwxTn5NFp/jx7Gnr4H v5qpy2O8/04fnpCVgd7Lrb0r1Hngr/tKjJ06EwR1SZ9OrrMfiDJcdSnD4vo0L8dl ocmwI4Gs2DDClWypODINYEc9MjQ3bJk1hOv/eNAM2QP5xflJaXTtimA= =QjtD -----END PGP SIGNATURE-----