Updated php-smarty packages fix security vulnerability
Publication date: 19 Oct 2018Modification date: 19 Oct 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-13982
Description
Smarty 3.1.32 or below is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files (CVE-2018-13982).
References
SRPMS
6/core
- php-smarty-3.1.33-1.2.mga6