CVE-2013-5958

EUVD-2022-3620
The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
sensiolabssymfony
2.0.0
sensiolabssymfony
2.0.1
sensiolabssymfony
2.0.2
sensiolabssymfony
2.0.3
sensiolabssymfony
2.0.4
sensiolabssymfony
2.0.5
sensiolabssymfony
2.0.6
sensiolabssymfony
2.0.7
sensiolabssymfony
2.0.8
sensiolabssymfony
2.0.9
sensiolabssymfony
2.0.10
sensiolabssymfony
2.0.11
sensiolabssymfony
2.0.12
sensiolabssymfony
2.0.13
sensiolabssymfony
2.0.14
sensiolabssymfony
2.0.15
sensiolabssymfony
2.0.16
sensiolabssymfony
2.0.17
sensiolabssymfony
2.0.18
sensiolabssymfony
2.0.19
sensiolabssymfony
2.0.20
sensiolabssymfony
2.0.21
sensiolabssymfony
2.0.22
sensiolabssymfony
2.0.23
sensiolabssymfony
2.0.24
sensiolabssymfony
2.1.0
sensiolabssymfony
2.1.1
sensiolabssymfony
2.1.2
sensiolabssymfony
2.1.3
sensiolabssymfony
2.1.4
sensiolabssymfony
2.1.5
sensiolabssymfony
2.1.6
sensiolabssymfony
2.1.7
sensiolabssymfony
2.1.8
sensiolabssymfony
2.1.9
sensiolabssymfony
2.1.10
sensiolabssymfony
2.1.11
sensiolabssymfony
2.1.12
sensiolabssymfony
2.2:dev
sensiolabssymfony
2.2.0
sensiolabssymfony
2.2.1
sensiolabssymfony
2.2.2
sensiolabssymfony
2.2.3
sensiolabssymfony
2.2.4
sensiolabssymfony
2.2.5
sensiolabssymfony
2.2.6
sensiolabssymfony
2.2.8
sensiolabssymfony
2.3.0
sensiolabssymfony
2.3.1
sensiolabssymfony
2.3.2
sensiolabssymfony
2.3.3
sensiolabssymfony
2.3.4
sensiolabssymfony
2.3.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
symfony
bookworm
5.4.23+dfsg-1+deb12u2
fixed
bullseye
4.4.19+dfsg-2+deb11u6
fixed
sid
6.4.13+dfsg-1
fixed
trixie
6.4.13+dfsg-1
fixed
Common Weakness Enumeration