Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Smarty could be made to crash or run programs if it received a specially
crafted template.
Software Description:
- smarty3: The compiling PHP template engine
Details:
It was discovered that Smarty incorrectly parsed blocks' names and
included files' names. A remote attacker with template writing permissions
could use this issue to execute arbitrary PHP code. (CVE-2022-29221)
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: smarty3 3.1.39-2ubuntu1.22.10.1 Ubuntu 22.04 LTS: smarty3 3.1.39-2ubuntu1.22.04.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-6012-1
CVE-2022-29221
Get the latest Linux and open source security news straight to your inbox.