security advisorycode executiondebian Smarty3, a template engine for PHP, allowed template authors to run restricted static php methods. The same authors could also run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, remote users were able to run arbitrary PHP . -------------------------------------------------------------------------Debian LTS Advisory DLA-2995-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany May 05, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : smarty3 Version : 3.1.31+20161214.1.c7d42e4+selfpack1-2+deb9u5 CVE ID : CVE-2021-21408 CVE-2021-29454 Debian Bug : 1010375 Smarty3, a template engine for PHP, allowed template authors to run restricted static php methods. The same authors could also run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, remote users were able to run arbitrary PHP code as well. For Debian 9 stretch, these problems have been fixed in version 3.1.31+20161214.1.c7d42e4+selfpack1-2+deb9u5. We recommend that you upgrade your smarty3 packages. For the detailed security status of smarty3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/smarty3 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-1234-1 resolves vulnerabilities in Jinja2, mitigating Python script execution threats.. Debian Smarty3 Code Execution PHP Security. . Severity: Important. LinuxSecurity.com Team
May 05, 2022 •Important Debian LTS