Today, patch versions for all actively maintained minor versions (2.5, 2.4 and 2.3 LTS) of the Symfony project have been published.
The version numbers of the patches are: 2.5.4, 2.4.9 and 2.3.19 and you should update to the latest patch release of you Symfony version ASAP because they fix this set of CVE listed vulnerabilities:
- CVE-2014-6072
- CVE-2014-5245
- CVE-2014-4931
- CVE-2014-6061
- CVE-2014-5244
Dive into the details at the Symfony blog:
- http://symfony.com/blog/symfony-2-5-4-released
- http://symfony.com/blog/symfony-2-4-9-released
- http://symfony.com/blog/symfony-2-3-19-released