Updated php-smarty package fixes security vulnerabilities
Publication date: 10 Jul 2021Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-26119 , CVE-2021-26120
Description
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode (CVE-2021-26119). Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring (CVE-2021-26120).
References
SRPMS
7/core
- php-smarty-3.1.39-1.mga7
8/core
- php-smarty-3.1.39-1.mga8