Ubuntu Security Notice USN-5348-1

Discussion in 'News Aggregator' started by Packet Storm, 29 Mar 2022.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 5348-1 - David Gnedt and Thomas Konrad discovered that Smarty was incorrectly sanitizing the paths present in the templates. An attacker could possibly use this use to read arbitrary files when controlling the executed template. It was discovered that Smarty was incorrectly sanitizing the paths present in the templates. An attacker could possibly use this use to read arbitrary files when controlling the executed template.

    Continue reading...
     

Share This Page

Loading...