USN-7377-1: Smarty vulnerability
27 March 2025
Smarty could be made to crash or run programs if it opened a specially crafted file.
Releases
Packages
- smarty4 - The compiling PHP template engine
Details
It was discovered that Smarty did not properly sanitize template file
names. An attacker could possibly use this issue to cause Smarty to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
Ubuntu 24.04
In general, a standard system update will make all the necessary changes.