Debian Security Update DSA-5151 smarty3 - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,974
Reaction score
80
Credits
-1,257
Several security vulnerabilities have been discovered in smarty3, the compiling PHP template engine. Template authors are able to run restricted static php methods or even arbitrary PHP code by crafting a malicious math string or by choosing an invalid {block} or {include} file name. If a math string was passed through as user provided data to the math function, remote users were able to run arbitrary PHP code as well.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top