From 85261a4d217482e1c124937d57ec98a0aabaee59 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 25 Sep 2022 17:34:04 +0100 Subject: gentoo auto-resync : 25:09:2022 - 17:34:03 --- metadata/glsa/glsa-202209-09.xml | 47 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 metadata/glsa/glsa-202209-09.xml (limited to 'metadata/glsa/glsa-202209-09.xml') diff --git a/metadata/glsa/glsa-202209-09.xml b/metadata/glsa/glsa-202209-09.xml new file mode 100644 index 000000000000..83bd6e71ede3 --- /dev/null +++ b/metadata/glsa/glsa-202209-09.xml @@ -0,0 +1,47 @@ + + + + Smarty: Multiple vulnerabilities + Multiple vulnerabilities have been found in Smarty, the worst of which could result in remote code execution + smarty + 2022-09-25 + 2022-09-25 + 830980 + 845180 + 870100 + remote + + + 4.2.1 + 4.2.1 + + + +

Smarty is a template engine for PHP. The "template security" feature of Smarty is designed to help reduce the risk of a system compromise when you have untrusted parties editing templates.

+
+ +

Multiple vulnerabilities have been discovered in Smarty. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Smarty users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-php/smarty-4.2.1" + +
+ + CVE-2018-25047 + CVE-2021-21408 + CVE-2021-29454 + CVE-2022-29221 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3