Advisories ยป MGASA-2018-0403

Updated php-smarty packages fix security vulnerability

Publication date: 19 Oct 2018
Modification date: 19 Oct 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-13982

Description

Smarty 3.1.32 or below is prone to a path traversal vulnerability due to
insufficient template code sanitization. This allows attackers controlling
the executed template code to bypass the trusted directory security
restriction and read arbitrary files (CVE-2018-13982).
                

References

SRPMS

6/core