Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Ubuntu 22.10 & 22.04 LTS USN-6012-1 Moderate: Smarty Template Exploit

ubuntu
Calendar Grey April 13, 2023
Scroller Ubuntu
Critical flaw in Smarty template permits remote execution of code, impacting Ubuntu versions 22.10 and 22.04 LTS. Ensure you update immediately!
Smarty could be made to crash or run programs if it received a specially crafted template.

Summary

Smarty could be made to crash or run programs if it received a specially

crafted template.

Software Description:

- smarty3: The compiling PHP template engine

Details:

It was discovered that Smarty incorrectly parsed blocks' names and

included files' names. A remote attacker with template writing permissions

could use this issue to execute arbitrary PHP code. (CVE-2022-29221)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   smarty3                         3.1.39-2ubuntu1.22.10.1

Ubuntu 22.04 LTS:
   smarty3                         3.1.39-2ubuntu1.22.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6012-1

  CVE-2022-29221

Severity
medium
Lowest
Low
Medium
High
Critical

April 13, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.