UBUNTU-CVE-2018-13982
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-13982
UBUNTU-CVE-2018-13982
Summary:
Details: Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
References: https://ubuntu.com/security/CVE-2018-13982, https://www.openwall.com/lists/oss-security/2018/09/17/4, https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180420-01_Smarty_Path_Traversal, https://ubuntu.com/security/notices/USN-5348-1, https://www.cve.org/CVERecord?id=CVE-2018-13982
Affected packages
Package
Name: smarty3
Purl: pkg:deb/ubuntu/[email protected]+20161214.1.c7d42e4+selfpack1-3ubuntu0.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
