-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 08 Nov 2024 08:01:14 +0100 Source: symfony Architecture: source Version: 6.4.14+dfsg-1 Distribution: unstable Urgency: medium Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org> Changed-By: David Prévot <taffit@debian.org> Changes: symfony (6.4.14+dfsg-1) unstable; urgency=medium . [ Nicolas Grekas ] * [HttpClient] Filter private IPs before connecting when Host == IP [CVE-2024-50342] * [HttpFoundation] Reject URIs that contain invalid characters [CVE-2024-50345] * [Process] Use %PATH% before %CD% to load the shell on Windows [CVE-2024-51736] . [ Fabien Potencier ] * Update VERSION for 6.4.14 . [ Wouter de Jong ] * Do not read from argv on non-CLI SAPIs [CVE-2024-50340] . [ David Prévot ] * Update 6.4.10+dfsg-1 changelog entry to document [CVE-2024-50341] * Update 6.4.11+dfsg-1 changelog entry to document [CVE-2024-50343] Checksums-Sha1: 640847a9d47c75743464ec6f4cee81778f09f4e0 16747 symfony_6.4.14+dfsg-1.dsc cb351e32ce360b5a63533b39e4b0ea319ae14441 8251184 symfony_6.4.14+dfsg.orig.tar.xz 46c8d3c2dbf82a81087b7c4b6ef5c438392cb35b 69440 symfony_6.4.14+dfsg-1.debian.tar.xz 1da0033decbbf622e79a5300cea8c3d158aba167 67890 symfony_6.4.14+dfsg-1_amd64.buildinfo Checksums-Sha256: a2dfe9b6d6a79793aa70345bfa3a3c4efe51af92e69d890613ccea63a2bf34f4 16747 symfony_6.4.14+dfsg-1.dsc cd19230f3e5e6b453132ec95a1574aef6729a45a7d8e759438b972ce764a498a 8251184 symfony_6.4.14+dfsg.orig.tar.xz b2100d73c5a90782ba9a1194a6a2f18eb88b6d3eb9761109299a039a955ba45a 69440 symfony_6.4.14+dfsg-1.debian.tar.xz f2bdb2b2076bd5e5363cb71ce9b3636d1c1fa5015eb57fa22b1e78d0ed78d729 67890 symfony_6.4.14+dfsg-1_amd64.buildinfo Files: 645b8febfb22727f3a7604bb6a6a628a 16747 php optional symfony_6.4.14+dfsg-1.dsc 87296a55c5cc5df124ab9e1b5c3be9d3 8251184 php optional symfony_6.4.14+dfsg.orig.tar.xz 05b8de3e129810d417a7576b7ed7a42a 69440 php optional symfony_6.4.14+dfsg-1.debian.tar.xz 758cf37db68001d3134fb6d031373f84 67890 php optional symfony_6.4.14+dfsg-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQFGBAEBCAAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmct1F8SHHRhZmZpdEBk ZWJpYW4ub3JnAAoJEAWMHPlE9r08y8kH/1PscoUSjEaLUxBJM0Y34C2OK4lADKYV 1AmAVtxOtzEaSTFpx6kYbTfXJFeU4NF7OTpqBSBEreETsXYDwrGqtLi8C2Oru/f+ Uq+zeGQJuNZ9Ox5Agsb+W7SiSzuKScybBSiCMCuyfno+MtOogY/MxkK/IFFKuWQQ j3vEW7piDvfmbKUgCmshDnoZ1RSNzp8PLuPrBPhK5+zn989bQDBR4H70TpaqnoZW JvNVR+8wNGJgC0TzW8G7hevEDzbG3cHPngd8wzy11IdpFt7TFe2SP6ojij4DJQQR mbwoNIVTpXiDQDdsK+tsccbRw8mp5KnOdXocQeorodw2/MZbSf/pNrk= =eeUh -----END PGP SIGNATURE-----