Vulnerability Bulletins

DSA-4094 smarty3 - security update

   
Affected software Debian
 
It was discovered that Smarty, a PHP template engine, was vulnerable tocode-injection attacks. An attacker was able to craft a filename incomments that could lead to arbitrary code execution on the host runningSmarty.

More info:

https://www.debian.org/security/2018/dsa-4094