Race condition In symfony/symfony
Description
Symfony Cryptographic Vulnerability The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.3.37, 2.6.13, 2.7.9 | ||
packagist | 2.3.37, 2.6.13, 2.7.9 | ||
packagist | 2.6.13, 2.7.9 | ||
debian 11 | 2.7.9+dfsg-1 | ||
debian 13 | 2.7.9+dfsg-1 | ||
debian 12 | 2.7.9+dfsg-1 | ||
debian 14 | 2.7.9+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8.