LWN.net Logo

php-smarty: arbitrary command execution

Package(s):php-Smarty CVE #(s):CVE-2009-1669
Created:May 28, 2009 Updated:August 18, 2010
Description: php-smarty has an arbitrary command execution vulnerability. From the Red Hat bug entry: The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.
Alerts:
Debian DSA-1919-2 2010-08-17
Gentoo 201006-13 2010-06-02
Debian DSA-1919-1 2009-10-25
Ubuntu USN-791-3 2009-06-24
Ubuntu USN-791-1 2009-06-24
Fedora FEDORA-2009-5520 2009-05-27
Fedora FEDORA-2009-5525 2009-05-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds