Vulnerability Bulletins

DSA-3343 twig - security update

   
Affected software Debian
 
James Kettle, Alain Tiemblo, Christophe Coevoet and Fabien Potencierdiscovered that twig, a templating engine for PHP, did not correctlyprocess its input. End users allowed to submit twig templates coulduse specially crafted code to trigger remote code execution, even insandboxed templates.

More info:

https://www.debian.org/security/2015/dsa-3343