Debian Security Advisory
DLA-2618-1 smarty3 -- LTS security update
- Date Reported:
- 08 Apr 2021
- Affected Packages:
- smarty3
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-13982, CVE-2021-26119, CVE-2021-26120.
- More information:
-
Several vulnerabilities were discovered in smarty3, a template engine for PHP.
- CVE-2018-13982
path traversal vulnerability due to insufficient sanitization of code in Smarty templates. This allows attackers controlling the Smarty template to bypass the trusted directory security restriction and read arbitrary files.
- CVE-2021-26119
allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
- CVE-2021-26120
allows code injection vulnerability via an unexpected function name after a {function name= substring.
For Debian 9 stretch, these problems have been fixed in version 3.1.31+20161214.1.c7d42e4+selfpack1-2+deb9u2.
We recommend that you upgrade your smarty3 packages.
For the detailed security status of smarty3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/smarty3
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
- CVE-2018-13982