-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2022-d39b2a755b 2022-10-07 13:13:03.413634 -------------------------------------------------------------------------------- Name : php-twig2 Product : Fedora 35 Version : 2.15.3 Release : 1.fc35 URL : https://twig.symfony.com Summary : The flexible, fast, and secure template engine for PHP Description : The flexible, fast, and secure template engine for PHP. * Fast: Twig compiles templates down to plain optimized PHP code. The overhead compared to regular PHP code was reduced to the very minimum. * Secure: Twig has a sandbox mode to evaluate untrusted template code. This allows Twig to be used as a template language for applications where users may modify the template design. * Flexible: Twig is powered by a flexible lexer and parser. This allows the developer to define its own custom tags and filters, and create its own DSL. Autoloader: /usr/share/php/Twig2/autoload.php -------------------------------------------------------------------------------- Update Information: **Version 2.15.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory) -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 29 2022 Remi Collet- 2.15.3-1 - update to 2.15.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2130764 - CVE-2022-39261 php-twig2: twig: Possibility to load a template outside a configured directory when using the filesystem loader [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2130764 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-d39b2a755b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue