Advisories ยป MGASA-2021-0335

Updated php-smarty package fixes security vulnerabilities

Publication date: 10 Jul 2021
Modification date: 10 Jul 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-26119 , CVE-2021-26120

Description

Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object
can be accessed in sandbox mode (CVE-2021-26119).

Smarty before 3.1.39 allows code injection via an unexpected function name
after a {function name= substring (CVE-2021-26120).
                

References

SRPMS

7/core

8/core