Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
172

Ubuntu 16.04 Smarty Important Cross-Site Scripting Risk USN-8272-1

Smarty could be made to run malicious JavaScript in the user's browser if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8272-1 May 19, 2026 smarty3 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Smarty could be made to run malicious JavaScript in the user's browser if it received specially crafted input. Software Description: - smarty3: The compiling PHP template engine Details: Takuya Aramaki discovered that Smarty did not properly escape JavaScript code. An attacker could possibly use this issue to conduct a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS smarty3 3.1.21-1ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8272-1 CVE-2023-28447 . Smarty could allow execution of malicious JavaScript in the user's browser, warranting critical attention and updates.. Smarty Security Issue, Ubuntu 16.04, Cross-Site Scripting, Security Advisory, JavaScript Exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 19, 2026 Important Ubuntu
172

Ubuntu 7377-1: Smarty Security Advisory Updates

Smarty could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7377-1 March 27, 2025 smarty vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS Summary: Smarty could be made to crash or run programs if it opened a specially crafted file. Software Description: - smarty4: The compiling PHP template engine Details: It was discovered that Smarty did not properly sanitize template file names. An attacker could possibly use this issue to cause Smarty to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 smarty4 4.3.1-1ubuntu0.24.10.1 Ubuntu 24.04 LTS smarty4 4.3.1-1ubuntu0.24.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7377-1 CVE-2024-35226 Package Information: https://launchpad.net/ubuntu/+source/smarty4/4.3.1-1ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/smarty4/4.3.1-1ubuntu0.24.04.1 . Smarty's flawed template sanitization can lead to crashes or code execution on Ubuntu. Update your system now for security.. smarty, crash, programs, opened, specially, crafted, ===============. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 27, 2025 Critical Ubuntu
172

Ubuntu 24.10 LTS: USN-7158-1 critical: smarty denial of service

Several security issues were fixed in Smarty.. ========================================================================== Ubuntu Security Notice USN-7158-1 December 12, 2024 smarty3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Smarty. Software Description: - smarty3: The compiling PHP template engine Details: It was discovered that Smarty incorrectly handled query parameters in requests. An attacker could possibly use this issue to inject arbitrary Javascript code, resulting in denial of service or potential execution of arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2018-25047, CVE-2023-28447) It was discovered that Smarty did not properly sanitize user input when generating templates. An attacker could, through PHP injection, possibly use this issue to execute arbitrary code. (CVE-2024-35226) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 smarty3 3.1.48-1ubuntu0.24.10.1 Ubuntu 24.04 LTS smarty3 3.1.48-1ubuntu0.24.04.1 Ubuntu 22.04 LTS smarty3 3.1.39-2ubuntu1.22.04.2 Ubuntu 20.04 LTS smarty3 3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1 Ubuntu 18.04 LTS smarty3 3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7158-1 CVE-2018-25047, CVE-2023-28447, CVE-2024-35226 Package Information: https://launchpad.net/ubuntu/+source/smarty3/3.1.39-2ubuntu1.22.04.2 https://launchpad.net/ubuntu/+source/smarty3/3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1 . The Ubuntu Security Advisory USN-7158-1 details corrective measures addressing Smarty vulnerabilities impacting several Ubuntu releases.. Smarty Security, Ubuntu Updates, Security Changes, PHP Template Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 13, 2024 Critical Ubuntu
87

Debian Bookworm: DSA-5830-1 moderate: Smarty PHP code injection

A security vulnerability was discovered in Smarty, a template engine for PHP, which could result in PHP code injection. For the stable distribution (bookworm), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5830-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 12, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : smarty4 CVE ID : CVE-2024-35226 A security vulnerability was discovered in Smarty, a template engine for PHP, which could result in PHP code injection. For the stable distribution (bookworm), this problem has been fixed in version 4.3.0-1+deb12u2. We recommend that you upgrade your smarty4 packages. For the detailed security status of smarty4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/smarty4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A flaw in Smarty4 poses risks for Debian bookworm users, now resolved in recent updates. Ensure to update packages for safety.. smarty security advisory, Debian updates, PHP code injection, Smarty vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 12, 2024 Important Debian
87

Debian: DSA-5826-1 critical: smarty3 code injection and XSS

Two security vulnerabilities were discovered in Smarty, a template engine for PHP, which could result in PHP code injection or cross-site scripting. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5826-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 10, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : smarty3 CVE ID : CVE-2023-28447 CVE-2024-35226 Two security vulnerabilities were discovered in Smarty, a template engine for PHP, which could result in PHP code injection or cross-site scripting. For the stable distribution (bookworm), these problems have been fixed in version 3.1.47-2+deb12u1. We recommend that you upgrade your smarty3 packages. For the detailed security status of smarty3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/smarty3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Two security flaws in the Smarty template framework addressed in Debian security notice DSA-5826-1, upgrade is advised.. smarty3 vulnerabilities, PHP security updates, Debian DSA-5826-1. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2024 Critical Debian
172

Ubuntu: 21.10 & 18.04 LTS Critical: Smarty Exploits and Threats

Several security issues were fixed in Smarty.. =========================================================================Ubuntu Security Notice USN-5348-1 March 28, 2022 smarty3 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Smarty. Software Description: - smarty3: The compiling PHP template engine Details: David Gnedt and Thomas Konrad discovered that Smarty was incorrectly sanitizing the paths present in the templates. An attacker could possibly use this use to read arbitrary files when controlling the executed template. (CVE-2018-13982) It was discovered that Smarty was incorrectly sanitizing the paths present in the templates. An attacker could possibly use this use to read arbitrary files when controlling the executed template. (CVE-2018-16831) It was discovered that Smarty was incorrectly validating security policy data, allowing the execution of static classes even when not permitted by the security settings. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-21408) It was discovered that Smarty was incorrectly managing access control to template objects, which allowed users to perform a sandbox escape. An attacker could possibly use this issue to send specially crafted input to applications that use Smarty and execute arbitrary code. (CVE-2021-26119) It was discovered that Smarty was not checking for special characters when setting function names during plugin compile operations. An attacker could possibly use this issue to send specially crafted input to applications that use Smarty and execute arbitrary code. (CVE-2021-26120) It was discovered that Smarty was incorrectly sanitizing characters in math strings processed by the math function. An attacker could possibly use this issue to send specially crafted input toapplications that use Smarty and execute arbitrary code. (CVE-2021-29454) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: smarty3 3.1.39-2ubuntu0.21.10.1 Ubuntu 18.04 LTS: smarty3 3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5348-1 CVE-2018-13982, CVE-2018-16831, CVE-2021-21408, CVE-2021-26119, CVE-2021-26120, CVE-2021-29454 Package Information: https://launchpad.net/ubuntu/+source/smarty3/3.1.39-2ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/smarty3/3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1 . Urgent vulnerabilities have been identified within Smarty impacting various versions of Ubuntu. Immediate patches are required to mitigate risks of potential breaches.. Smarty Security Update, Ubuntu Advisory, Threat Management, PHP Template Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 28, 2022 Critical Ubuntu
91

Gentoo: GLSA-202105-06 Normal: Smarty Remote Code Execution Threats

Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Smarty: Multiple vulnerabilities Date: May 26, 2021 Bugs: #772206 ID: 202105-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code. Background ========= Smarty is a template engine for PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-php/smarty < 3.1.39 > = 3.1.39 Description ========== Multiple vulnerabilities have been discovered in Smarty template engine. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Smarty template engine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-php/smarty-3.1.39" References ========= [ 1 ] CVE-2021-26119 https://nvd.nist.gov/vuln/detail/CVE-2021-26119 [ 2 ] CVE-2021-26120 https://nvd.nist.gov/vuln/detail/CVE-2021-26120 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-06 Concerns? ======== Security is aprimary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A recent Gentoo security advisory warns of critical vulnerabilities in the Smarty template engine, risking code execution and data exposure for web apps that utilize it.. Smarty Template Engine,Gentoo Security Advisory,Remote Code Execution. . LinuxSecurity.com Team

Calendar%202 May 26, 2021 Gentoo
91

Gentoo: GLSA-201006-13 Normal: Smarty Critical PHP Execution Issue

Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201006-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Smarty: Multiple vulnerabilities Date: June 02, 2010 Bugs: #212147, #243856, #270494 ID: 201006-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in the Smarty template engine might allow remote attackers to execute arbitrary PHP code. Background ========= Smarty is a template engine for PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-php/smarty < 2.6.23 > = 2.6.23 Description ========== Multiple vulnerabilities have been discovered in Smarty: * The vendor reported that the modifier.regex_replace.php plug-in contains an input sanitation flaw related to the ASCII NUL character (CVE-2008-1066). * The vendor reported that the _expand_quoted_text() function in libs/Smarty_Compiler.class.php contains an input sanitation flaw via multiple vectors (CVE-2008-4810, CVE-2008-4811). * Nine:Situations:Group::bookoo reported that the smarty_function_math() function in libs/plugins/function.math.php contains input sanitation flaw (CVE-2009-1669). Impact ===== These issues might allow a remote attacker to execute arbitrary PHP code. Workaround ========= There is no known workaround at this time. Resolution ========= All Smarty users should upgrade to an unaffected version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-php/smarty-2.6.23" NOTE: This is a legacy GLSA. Updates for all affected architectures are available since June 2, 2009. It is likely that your system is already no longer affected by this issue. References ========= [ 1 ] CVE-2008-1066 https://www.cve.org/CVERecord?id=CVE-2008-1066 [ 2 ] CVE-2008-4810 https://www.cve.org/CVERecord?id=CVE-2008-4810 [ 3 ] CVE-2008-4811 https://www.cve.org/CVERecord?id=CVE-2008-4811 [ 4 ] CVE-2009-1669 https://www.cve.org/CVERecord?id=CVE-2009-1669 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201006-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Various security flaws found in the Smarty template framework could lead to remote code execution threats; ensure you update to protected versions.. Smarty Template Flaw, Remote Code Execution, Gentoo Security Update. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2010 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200