Advisories ยป MGASA-2018-0118

Updated php-smarty packages fix security vulnerability

Publication date: 06 Feb 2018
Modification date: 06 Feb 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-1000480

Description

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling
fetch() or display() functions on custom resources that does not sanitize
template name(CVE-2017-1000480).
                

References

SRPMS

6/core

5/core