Updated php-smarty packages fix security vulnerability
Publication date: 06 Feb 2018Modification date: 06 Feb 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-1000480
Description
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name(CVE-2017-1000480).
References
SRPMS
6/core
- php-smarty-3.1.21-3.1.mga6
5/core
- php-smarty-3.1.21-1.1.mga5