Gentoo: GLSA-200503-35: Smarty: Template vulnerability
Summary
Gentoo Linux Security Advisory [UPDATE] GLSA 200503-35:02
https://security.gentoo.org/
Severity: High
Title: Smarty: Template vulnerability
Date: March 30, 2005
Updated: April 09, 2005
Bugs: #86488
ID: 200503-35:02
Update
=====
New ways of bypassing Smarty's "Template security" were found and
fixed in Smarty. Users making use of that feature are encouraged
to upgrade to version 2.6.9.
The updated sections appear below.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-php/smarty < 2.6.9 >= 2.6.9
==========
A vulnerability has been discovered within the regex_replace modifier
of the Smarty templates when allowing access to untrusted users.
Furthermore, ...
Resolution
References
Availability
Concerns
Background