USN-791-3: Smarty vulnerability
24 June 2009
Smarty vulnerability
Releases
Packages
- smarty -
Details
It was discovered that Smarty did not correctly filter certain math
inputs. A remote attacker using Smarty via a web service could exploit
this to execute subsets of shell commands as the web server user.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.04
In general, a standard system upgrade is sufficient to effect the
necessary changes.
References
Related notices
- USN-791-1: moodle