Archives


Master Symfony2 fundamentals

Be trained by SensioLabs experts (2 to 6 day sessions -- French or English).
trainings.sensiolabs.com

Symfony hosting done right

ServerGrove, outstanding support at the right price for your Symfony hosting needs.
servergrove.com

L'audit Qualité par SensioLabs

200 points de contrôle de votre applicatif web.
audit.sensiolabs.com

Fabien Potencier
symfony 1.0.5 released (security fix)
by Fabien Potencier – June 25, 2007 – 29 comments

I've just released symfony 1.0.5. If you use the symfony built-in phpmailer (and you do if you use the ->sendMail() method in your actions), you must upgrade to this release or apply the following patch: http://trac.symfony-project.com/trac/changeset/4380?format=diff&new=4380.

PHPMailer has a remote command execution vulnerability if you have configured it to use sendmail. You can find more information about this issue here: http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/

Here are all bugs fixed in this release:

  • r4387: fixed input_date_range_tag - Illegal attributes in input tags (#1883)
  • r4385: fixed issue relating to lock files (#1874)
  • r4380: fixed vulnerability in phpmailer with sender (#1871)
  • r4323: fixed DOMDocument E_STRICT warning and trans-unit max id in XLIFF support
  • r4320: fixed sfToolkit::isUTF8() broken for strings larger than some number
  • r4305: added i18n schema for MySQL and SQLite in API documentation

As for every 1.0.X release, after upgrading to 1.0.5, don't forget to clear the cache of your projects.

Add a Comment

You must be connected to post a comment.

Comments RSS

  • gravatar
    #1 E.T.Cook said on the 2007/06/25 at 23:18
    I just upgraded, and when I do a symfony -V, the version went down from 1.0.4 to 1.0.3 ironically...and i should be 1.0.5! Is it just semantic?
  • gravatar
    #2 rihad said on the 2007/06/27 at 12:30
    I have a suggestion: make 1.0.x 0.9.x or some such, and release 1.0 as soon as Symfony has validation at the model, not controller, level (design issue).
  • gravatar
    #3 Adriaan said on the 2007/07/08 at 16:30
    Nice update... Only trouble...

    -bash-3.1$ symfony propel-build-all

    Fatal error: Unsupported operand types in /usr/share/pear/symfony/util/Spyc.class.php on line 667

    Call Stack:
    0.0007 40128 1. {main}() /usr/bin/symfony:0
    0.0026 86816 2. include('/usr/share/pear/data/symfony/bin/symfony.php') /usr/bin/symfony:39
    0.1036 1622008 3. pakeApp->run() /usr/share/pear/data/symfony/bin/symfony.php:171
    0.1176 1710944 4. pakeTask->invoke() /usr/share/pear/symfony/vendor/pake/pakeApp.class.php:143
    0.1193 1711296 5. pakeTask->execute() /usr/share/pear/symfony/vendor/pake/pakeTask.class.php:181
    0.1194 1711296 6. call_user_func_array() /usr/share/pear/symfony/vendor/pake/pakeTask.class.php:218
    0.1194 1711296 7. run_propel_build_all() /usr/share/pear/symfony/vendor/pake/pakeTask.class.php:0
    0.1194 1711296 8. run_propel_build_model() /usr/share/pear/data/symfony/tasks/sfPakePropel.php:159
    0.1194 1711296 9. _propel_convert_yml_schema() /usr/share/pear/data/symfony/tasks/sfPakePropel.php:172
    0.4383 1928136 10. sfPropelDatabaseSchema->loadYAML() /usr/share/pear/data/symfony/tasks/sfPakePropel.php:71
    0.4392 1943328 11. sfYaml::load() /usr/share/pear/symfony/addon/propel/sfPropelDatabaseSchema.class.php:31
    0.4461 2141880 12. Spyc->load() /usr/share/pear/symfony/util/sfYaml.class.php:59
    0.4524 2147816 13. Spyc->_parseLine() /usr/share/pear/symfony/util/Spyc.class.php:256
    0.4525 2147960 14. Spyc->_toType() /usr/share/pear/symfony/util/Spyc.class.php:591
  • gravatar
    #4 judas_iscariote said on the 2007/07/12 at 05:20
    What about removing phpmailer completely and switch the symfony code to SwiftMailer. ?
  • gravatar
    #5 boombox said on the 2007/08/18 at 11:57
    Hi! nice site !
    <a href="http://guardswatches.info/replica-watches/swiss-rolex-watch.php">swiss rolex watch</a>
    <a href="http://guardswatches.info/replica-watches/best-prices-on-rolex-watches.php">best prices on rolex watches</a>
    http://guardswatches.info/replica-watches/chopard-replica-watches.php
    <a href="http://guardswatches.info/replica-watches/1930's-replica-watch.php">1930's replica watch</a>
    <a href="http://guardswatches.info/replica-watches/replica-watch-japanese-movement.php">replica watch japanese movement</a>
    <a href="http://guardswatches.info/replica-watches/watch-replica-lange-soehne.php">watch replica lange soehne</a>
    http://guardswatches.info/replica-watches/swiss-rolex-replica-watch-ebay.php
    <a href="http://guardswatches.info/replica-watches/instructions-for-rolex-daytona-watch.php">instructions for rolex daytona watch</a>
    <a href="http://guardswatches.info/replica-watches/how-a-rolex-watch-works.php">how a rolex watch works</a>
    http://guardswatches.info/replica-watches/designer-replica-discount-watches-free-shipping.php
  • gravatar
    #6 Yair said on the 2007/08/18 at 18:46
    You have a nice site ;)
    <a href="http://aimringtones.info/replica-watches/replica-classics-watches.php">replica classics watches</a>
    <a href="http://aimringtones.info/rolex-watches/rolex-watches-wholesale.php">rolex watches wholesale</a>
    http://aimringtones.info/replica-watches/best-replica-watches.php
    http://aimringtones.info/replica-watches/rolex-watch-characteristics.php
    http://aimringtones.info/replica-watches/rolex-watches-replicas.php
    http://aimringtones.info/rolex-watches/rolex-president-watches.php
    http://aimringtones.info/replica-watches/rolex-presidents,-rose-gold,-watches.php
    http://aimringtones.info/replica-watches/ladies-rolex-datejust-watches.php
    http://aimringtones.info/replica-watches/replica-watch-handbags.php
    http://aimringtones.info/replica-watches/authorized-rolex-watch-dealers.php
    <a href="http://aimringtones.info/replica-watches/replica-rolex-daytona.php">replica rolex daytona</a>
    <a href="http://aimringtones.info/replica-watches/rolex-watches-antique.php">rolex watches antique</a>
    <a href="http://aimringtones.info/replica-watches/replica-swiss-watch.php">replica swiss watch</a>
  • gravatar
    #7 Tomko said on the 2007/08/19 at 23:39
    You have a nice site ;)
    <a href="http://mentalringtones.info/viagra-online/viagra-discount-online.php">viagra discount online</a>
    http://mentalringtones.info/viagra-online/online-viagra-student-loan-consolidation.php
    <a href="http://mentalringtones.info/viagra-online/online-prescription-viagra-phentermine-meridia-adipex.php">online prescription viagra phentermine meridia adipex</a>
    <a href="http://mentalringtones.info/viagra-online/medicine-online-viagra.php">medicine online viagra</a>
    <a href="http://mentalringtones.info/viagra-online/generic-viagra-online-order.php">generic viagra online order</a>
    <a href="http://mentalringtones.info/viagra-online/buy-get-online-prescription-viagra.php">buy get online prescription viagra</a>
    http://mentalringtones.info/viagra-online/buy-com-lvivhost-online-viagra.php
    <a href="http://mentalringtones.info/viagra-online/viagra-buying-online.php">viagra buying online</a>
    <a href="http://mentalringtones.info/viagra-online/00000e04.htm-event-member-online-viagra-yale.org.uk.php">00000e04.htm event member online viagra yale.org.uk</a>
    http://mentalringtones.info/viagra-online/buy-lvivhostcom-online-viagra-viagra.php
    <a href="http://mentalringtones.info/viagra-online/levitra,-cialis,-viagra-online-sales.php">levitra, cialis, viagra online sales</a>
    http://mentalringtones.info/viagra-online/free-online-sample-viagra.php
    <a href="http://mentalringtones.info/viagra-online/viagra-sales-online.php">viagra sales online</a>
  • gravatar
    #8 Tixier said on the 2007/08/19 at 23:39
    You have a nice site ;)
    <a href="http://mentalringtones.info/viagra-online/viagra-discount-online.php">viagra discount online</a>
    <a href="http://mentalringtones.info/viagra-online/buying-viagra-online-in-britain.php">buying viagra online in britain</a>
    <a href="http://mentalringtones.info/viagra-online/pfizer-viagra-online.php">pfizer viagra online</a>
    http://mentalringtones.info/viagra-online/buy-buy-levitra-levitra-online-online-viagra-viagra.php
    <a href="http://mentalringtones.info/viagra-online/buy-discount-viagra-online.php">buy discount viagra online</a>
    <a href="http://mentalringtones.info/viagra-online/is-it-legal-to-order-viagra-online.php">is it legal to order viagra online</a>
    <a href="http://mentalringtones.info/viagra-online/viagra-online-discount.php">viagra online discount</a>
    http://mentalringtones.info/viagra-online/buying-viagra-online-in-britain.php
    http://mentalringtones.info/viagra-online/viagra-online.php
    <a href="http://mentalringtones.info/viagra-online/get-viagra-online.php">get viagra online</a>
    <a href="http://mentalringtones.info/viagra-online/online-sale-viagra.php">online sale viagra</a>
    <a href="http://mentalringtones.info/viagra-online/discount-viagra-online.php">discount viagra online</a>
    <a href="http://mentalringtones.info/viagra-online/generic-brand-of-viagra-online.php">generic brand of viagra online</a>
  • gravatar
    #9 Turunen said on the 2007/08/19 at 23:39
    You have a nice site ;)
    http://mentalringtones.info/viagra-online/tramadol-viagra-fetal-monitor-online-pharmacy.php
    http://mentalringtones.info/viagra-online/viagra-online-pharmacy.php
    http://mentalringtones.info/viagra-online/no-prescription-order-viagra-online.php
    <a href="http://mentalringtones.info/viagra-online/online-troya.up2.co.il-viagra.php">online troya.up2.co.il viagra</a>
    http://mentalringtones.info/viagra-online/linkdomain-buy-online-viagra-info-domain.php
    http://mentalringtones.info/viagra-online/online-pharmacy-prescription-drug-viagra.php
    http://mentalringtones.info/viagra-online/herpes-online-prescription-viagra.php
    <a href="http://mentalringtones.info/viagra-online/cheap-cheap-generic-generic-online-online-viagra-viagra.php">cheap cheap generic generic online online viagra viagra</a>
    <a href="http://mentalringtones.info/viagra-online/free-online-viagra.php">free online viagra</a>
    http://mentalringtones.info/viagra-online/online-ritalin-viagra-paypal.php
    <a href="http://mentalringtones.info/viagra-online/buy-vitamins-merchant-accounts-viagra-sale-online.php">buy vitamins merchant accounts viagra sale online</a>
    <a href="http://mentalringtones.info/viagra-online/buy-cheapest-viagra-online.php">buy cheapest viagra online</a>
    <a href="http://mentalringtones.info/viagra-online/buy-generic-viagra-online.php">buy generic viagra online</a>
  • gravatar
    #10 weddingc said on the 2007/08/20 at 12:33
    Hi! nice site !
    http://mentalringtones.info/cialis/buy-cialis-cialas.php
    http://mentalringtones.info/cialis/zenegraviagra-levitra-cialis-apcalis-regalis-zenegra.php
    http://mentalringtones.info/cialis/to-cialis-buy-where.php
    http://mentalringtones.info/cialis/buy-cheap-cialis-online.php
    http://mentalringtones.info/cialis/purchasing-online-generic-cialis-tadalafil.php
    http://mentalringtones.info/cialis/cialis-kokemuksia.php
    <a href="http://mentalringtones.info/cialis/free-cialis-softtabs-online.php">free cialis softtabs online</a>
    <a href="http://mentalringtones.info/cialis/cialis-online-rezeptfrei.php">cialis online rezeptfrei</a>
    http://mentalringtones.info/cialis/buy-online-cialis.php
    http://mentalringtones.info/cialis/cialis-generic-price.php
  • gravatar
    #11 Hillary said on the 2007/08/20 at 20:55
    !!! If you don't want to receive this spam just email me at abuse@yourfreehandbags.biz with url of your site and I'll take you off the list.
    !!!

    <a href="http://mentalringtones.info/tramadol/buy-dream-online-pharmaceutical-tramadol.php">buy dream online pharmaceutical tramadol</a>
    <a href="http://mentalringtones.info/tramadol/tramadol-overnight-fedex.php">tramadol overnight fedex</a>
    <a href="http://mentalringtones.info/tramadol/creditbuy-tramadol.php">creditbuy tramadol</a>
    http://mentalringtones.info/tramadol/price-search-tramadol.php
    http://mentalringtones.info/tramadol/hcl-tab-tramadol.php
    http://mentalringtones.info/tramadol/tramadol-tablet.php
    http://mentalringtones.info/tramadol/where-to-buy-tramadol.php
    <a href="http://mentalringtones.info/tramadol/tramadol-overseas-cheap.php">tramadol overseas cheap</a>
    <a href="http://mentalringtones.info/tramadol/depression-tramadol.php">depression tramadol</a>
    http://mentalringtones.info/tramadol/tramadol-discount.php
    <a href="http://mentalringtones.info/tramadol/effects-of-tramadol.php">effects of tramadol</a>
    http://mentalringtones.info/tramadol/tramadol-buy-on-line.php
    http://mentalringtones.info/tramadol/overdose-tramadol.php
    <a href="http://mentalringtones.info/tramadol/tramadol-withdrawal.php">tramadol withdrawal</a>
    http://mentalringtones.info/tramadol/cetirizine-tramadol.php
    <a href="http://mentalringtones.info/tramadol/how-do-i-order-tramadol-legally-online-help.php">how do i order tramadol legally online help</a>
    http://mentalringtones.info/tramadol/tramadol-very.php
    <a href="http://mentalringtones.info/tramadol/side-effects-tramadol-hcl.php">side effects tramadol hcl</a>
    http://mentalringtones.info/tramadol/tramadol-or-ultram-withdrawal-abrup.php
    http://mentalringtones.info/tramadol/imitrex-buy-tramadol.php

    End ^) See you
  • gravatar
    #12 children said on the 2007/08/21 at 09:31
    Hi! nice site !
    <a href="http://cialirio.biz/replica-watches/replica-watches-uk.php">replica watches uk</a>
    <a href="http://cialirio.biz/replica-watches/cheap-fake-rolex.php">cheap fake rolex</a>
    http://cialirio.biz/rolex-watches/importer-of-used-rolex-watches.php
    http://cialirio.biz/replica-watches/fake-swiss-rolex-watches-replica.php
    http://cialirio.biz/replica-watches/replica-mont-blanc-sports-watch.php
    <a href="http://cialirio.biz/replica-watches/versace-replica-watches.php">versace replica watches</a>
    <a href="http://cialirio.biz/replica-watches/swiss-watch-replica-rolex.php">swiss watch replica rolex</a>
    http://cialirio.biz/replica-watches/best-replica-rolex-identical.php
    http://cialirio.biz/replica-watches/patek-phillipe-replica-watch.php
    http://cialirio.biz/replica-watches/replica-bristling-emergency-watch.php
  • gravatar
    #13 Van Prooyen said on the 2007/08/21 at 11:02
    You have a nice site ;)
    http://handbagssite.biz/replica-handbags/replica-wholesale-handbags.php
    http://handbagssite.biz/replica-handbags/gucci-replica-handbags-aaa.php
    <a href="http://handbagssite.biz/chanel-handbags/who-makes-chanel-handbags.php">who makes chanel handbags</a>
    <a href="http://handbagssite.biz/chanel-handbags/chanel-handbags.php">chanel handbags</a>
    <a href="http://handbagssite.biz/replica-handbags/replica-kate-spade-handbags.php">replica kate spade handbags</a>
    http://handbagssite.biz/chanel-handbags/chanel-handbags-wholesale.php
    <a href="http://handbagssite.biz/replica-handbags/cheap-prada-purse-inexpensive-fake-replica-knockoff.php">cheap prada purse inexpensive fake replica knockoff</a>
    <a href="http://handbagssite.biz/chanel-handbags/chanel-cambon-handbag.php">chanel cambon handbag</a>
    <a href="http://handbagssite.biz/replica-handbags/designer-handbags-replica-tiffany-jewlery.php">designer handbags replica tiffany jewlery</a>
    <a href="http://handbagssite.biz/replica-handbags/beijo-replica-handbags-wholesale.php">beijo replica handbags wholesale</a>
    http://handbagssite.biz/replica-handbags/hermes-birkin-replica-handbags.php
    <a href="http://handbagssite.biz/chanel-handbags/authentic-chanel-handbag-shoes.php">authentic chanel handbag shoes</a>
    http://handbagssite.biz/replica-handbags/replica-handbags-loui-vuitton.php
  • gravatar
    #14 i2rqcs6uuz said on the 2007/08/22 at 02:08
    203r126t36kfkggc <a href = http://www.543871.com/342581.html > uh2lxu9d2aywx9rg6 </a> [URL=http://www.377715.com/150917.html] p1dqup92elv91nm [/URL] dwuvv4c6n9bfp1
  • gravatar
    #15 uy2buidtpv said on the 2007/08/22 at 02:08
    d1hfxct27nb <a href = http://www.643637.com/903797.html > mw4bq89h4 </a> [URL=http://www.496681.com/851152.html] ybfceikh [/URL] 3fk5sge1ep8y3q
  • gravatar
    #16 t388jouvav said on the 2007/08/22 at 02:08
    ihegogk67 <a href = http://www.1074182.com/905165.html > m3x3nlt7ywm </a> [URL=http://www.433314.com/177368.html] ld8j48p56o5ob214p [/URL] 0d6h8e2fggwll
  • gravatar
    #17 99ecoicxn5 said on the 2007/08/22 at 02:08
    pe32mbnq8nsn <a href = http://www.682453.com/428527.html > 4h5nzh1rze </a> [URL=http://www.731632.com/907126.html] ho17tcubwjfbo18e4 [/URL] yio2sppv09ncvsrws
  • gravatar
    #18 t388jouvav said on the 2007/08/22 at 02:08
    ihegogk67 [URL=http://www.433314.com/177368.html] ld8j48p56o5ob214p [/URL] 0d6h8e2fggwll
  • gravatar
    #19 99ecoicxn5 said on the 2007/08/22 at 02:08
    pe32mbnq8nsn [URL=http://www.731632.com/907126.html] ho17tcubwjfbo18e4 [/URL] yio2sppv09ncvsrws
  • gravatar
    #20 uy2buidtpv said on the 2007/08/22 at 02:08
    d1hfxct27nb [URL=http://www.496681.com/851152.html] ybfceikh [/URL] 3fk5sge1ep8y3q
  • gravatar
    #21 i2rqcs6uuz said on the 2007/08/22 at 02:08
    203r126t36kfkggc [URL=http://www.377715.com/150917.html] p1dqup92elv91nm [/URL] dwuvv4c6n9bfp1
  • gravatar
    #22 luzabeqjbu said on the 2007/08/22 at 02:08
    dgmz9jpzi <a href = http://www.341400.com/1015612.html > v4my58vw9k4cbif5 </a> [URL=http://www.938077.com/227934.html] wr3zu3do [/URL] bh7f9rxufjz5bw4g
  • gravatar
    #23 i2rqcs6uuz said on the 2007/08/22 at 02:08
    203r126t36kfkggc http://www.666894.com/957865.html dwuvv4c6n9bfp1
  • gravatar
    #24 uy2buidtpv said on the 2007/08/22 at 02:08
    d1hfxct27nb http://www.458480.com/608993.html 3fk5sge1ep8y3q
  • gravatar
    #25 99ecoicxn5 said on the 2007/08/22 at 02:08
    pe32mbnq8nsn http://www.1034214.com/1077447.html yio2sppv09ncvsrws
  • gravatar
    #26 luzabeqjbu said on the 2007/08/22 at 02:08
    dgmz9jpzi [URL=http://www.938077.com/227934.html] wr3zu3do [/URL] bh7f9rxufjz5bw4g
  • gravatar
    #27 uy2buidtpv said on the 2007/08/22 at 02:08
    d1hfxct27nb lgc9358qg 3fk5sge1ep8y3q
  • gravatar
    #28 t388jouvav said on the 2007/08/22 at 02:08
    ihegogk67 http://www.369106.com/949629.html 0d6h8e2fggwll
  • gravatar
    #29 luzabeqjbu said on the 2007/08/22 at 02:08
    dgmz9jpzi http://www.194161.com/316310.html bh7f9rxufjz5bw4g