Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Smarty could be made to run malicious JavaScript in the user's browser if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8272-1 May 19, 2026 smarty3 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Smarty could be made to run malicious JavaScript in the user's browser if it received specially crafted input. Software Description: - smarty3: The compiling PHP template engine Details: Takuya Aramaki discovered that Smarty did not properly escape JavaScript code. An attacker could possibly use this issue to conduct a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS smarty3 3.1.21-1ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8272-1 CVE-2023-28447 . Smarty could allow execution of malicious JavaScript in the user's browser, warranting critical attention and updates.. Smarty Security Issue, Ubuntu 16.04, Cross-Site Scripting, Security Advisory, JavaScript Exploit. . Severity: Important. LinuxSecurity.com Team
Smarty could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7377-1 March 27, 2025 smarty vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS Summary: Smarty could be made to crash or run programs if it opened a specially crafted file. Software Description: - smarty4: The compiling PHP template engine Details: It was discovered that Smarty did not properly sanitize template file names. An attacker could possibly use this issue to cause Smarty to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 smarty4 4.3.1-1ubuntu0.24.10.1 Ubuntu 24.04 LTS smarty4 4.3.1-1ubuntu0.24.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7377-1 CVE-2024-35226 Package Information: https://launchpad.net/ubuntu/+source/smarty4/4.3.1-1ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/smarty4/4.3.1-1ubuntu0.24.04.1 . Smarty's flawed template sanitization can lead to crashes or code execution on Ubuntu. Update your system now for security.. smarty, crash, programs, opened, specially, crafted, ===============. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Smarty.. ========================================================================== Ubuntu Security Notice USN-7158-1 December 12, 2024 smarty3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Smarty. Software Description: - smarty3: The compiling PHP template engine Details: It was discovered that Smarty incorrectly handled query parameters in requests. An attacker could possibly use this issue to inject arbitrary Javascript code, resulting in denial of service or potential execution of arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2018-25047, CVE-2023-28447) It was discovered that Smarty did not properly sanitize user input when generating templates. An attacker could, through PHP injection, possibly use this issue to execute arbitrary code. (CVE-2024-35226) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 smarty3 3.1.48-1ubuntu0.24.10.1 Ubuntu 24.04 LTS smarty3 3.1.48-1ubuntu0.24.04.1 Ubuntu 22.04 LTS smarty3 3.1.39-2ubuntu1.22.04.2 Ubuntu 20.04 LTS smarty3 3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1 Ubuntu 18.04 LTS smarty3 3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7158-1 CVE-2018-25047, CVE-2023-28447, CVE-2024-35226 Package Information: https://launchpad.net/ubuntu/+source/smarty3/3.1.39-2ubuntu1.22.04.2 https://launchpad.net/ubuntu/+source/smarty3/3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1 . The Ubuntu Security Advisory USN-7158-1 details corrective measures addressing Smarty vulnerabilities impacting several Ubuntu releases.. Smarty Security, Ubuntu Updates, Security Changes, PHP Template Issues. . Severity: Critical. LinuxSecurity.com Team
A security vulnerability was discovered in Smarty, a template engine for PHP, which could result in PHP code injection. For the stable distribution (bookworm), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5830-1
Two security vulnerabilities were discovered in Smarty, a template engine for PHP, which could result in PHP code injection or cross-site scripting. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5826-1
Several security issues were fixed in Smarty.. =========================================================================Ubuntu Security Notice USN-5348-1 March 28, 2022 smarty3 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Smarty. Software Description: - smarty3: The compiling PHP template engine Details: David Gnedt and Thomas Konrad discovered that Smarty was incorrectly sanitizing the paths present in the templates. An attacker could possibly use this use to read arbitrary files when controlling the executed template. (CVE-2018-13982) It was discovered that Smarty was incorrectly sanitizing the paths present in the templates. An attacker could possibly use this use to read arbitrary files when controlling the executed template. (CVE-2018-16831) It was discovered that Smarty was incorrectly validating security policy data, allowing the execution of static classes even when not permitted by the security settings. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-21408) It was discovered that Smarty was incorrectly managing access control to template objects, which allowed users to perform a sandbox escape. An attacker could possibly use this issue to send specially crafted input to applications that use Smarty and execute arbitrary code. (CVE-2021-26119) It was discovered that Smarty was not checking for special characters when setting function names during plugin compile operations. An attacker could possibly use this issue to send specially crafted input to applications that use Smarty and execute arbitrary code. (CVE-2021-26120) It was discovered that Smarty was incorrectly sanitizing characters in math strings processed by the math function. An attacker could possibly use this issue to send specially crafted input toapplications that use Smarty and execute arbitrary code. (CVE-2021-29454) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: smarty3 3.1.39-2ubuntu0.21.10.1 Ubuntu 18.04 LTS: smarty3 3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5348-1 CVE-2018-13982, CVE-2018-16831, CVE-2021-21408, CVE-2021-26119, CVE-2021-26120, CVE-2021-29454 Package Information: https://launchpad.net/ubuntu/+source/smarty3/3.1.39-2ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/smarty3/3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1 . Urgent vulnerabilities have been identified within Smarty impacting various versions of Ubuntu. Immediate patches are required to mitigate risks of potential breaches.. Smarty Security Update, Ubuntu Advisory, Threat Management, PHP Template Issue. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Smarty: Multiple vulnerabilities Date: May 26, 2021 Bugs: #772206 ID: 202105-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code. Background ========= Smarty is a template engine for PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-php/smarty < 3.1.39 > = 3.1.39 Description ========== Multiple vulnerabilities have been discovered in Smarty template engine. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Smarty template engine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-php/smarty-3.1.39" References ========= [ 1 ] CVE-2021-26119 https://nvd.nist.gov/vuln/detail/CVE-2021-26119 [ 2 ] CVE-2021-26120 https://nvd.nist.gov/vuln/detail/CVE-2021-26120 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-06 Concerns? ======== Security is aprimary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201006-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Smarty: Multiple vulnerabilities Date: June 02, 2010 Bugs: #212147, #243856, #270494 ID: 201006-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code. Background ========= Smarty is a template engine for PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-php/smarty < 2.6.23 > = 2.6.23 Description ========== Multiple vulnerabilities have been discovered in Smarty: * The vendor reported that the modifier.regex_replace.php plug-in contains an input sanitation flaw related to the ASCII NUL character (CVE-2008-1066). * The vendor reported that the _expand_quoted_text() function in libs/Smarty_Compiler.class.php contains an input sanitation flaw via multiple vectors (CVE-2008-4810, CVE-2008-4811). * Nine:Situations:Group::bookoo reported that the smarty_function_math() function in libs/plugins/function.math.php contains input sanitation flaw (CVE-2009-1669). Impact ===== These issues might allow a remote attacker to execute arbitrary PHP code. Workaround ========= There is no known workaround at this time. Resolution ========= All Smarty users should upgrade to an unaffected version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-php/smarty-2.6.23" NOTE: This is a legacy GLSA. Updates for all affected architectures are available since June 2, 2009. It is likely that your system is already no longer affected by this issue. References ========= [ 1 ] CVE-2008-1066 https://www.cve.org/CVERecord?id=CVE-2008-1066 [ 2 ] CVE-2008-4810 https://www.cve.org/CVERecord?id=CVE-2008-4810 [ 3 ] CVE-2008-4811 https://www.cve.org/CVERecord?id=CVE-2008-4811 [ 4 ] CVE-2009-1669 https://www.cve.org/CVERecord?id=CVE-2009-1669 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201006-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.