Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 386281 (CVE-2009-5052) - <dev-php/smarty-3.0: Multiple vulnerabilities (CVE-2009-{5052,5054},CVE-2010-{4722,4723,4724,4725,4726,4727})
Summary: <dev-php/smarty-3.0: Multiple vulnerabilities (CVE-2009-{5052,5054},CVE-2010-...
Alias: CVE-2009-5052
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Whiteboard: B? [noglsa]
Depends on: CVE-2012-4437
  Show dependency tree
Reported: 2011-10-08 13:22 UTC by GLSAMaker/CVETool Bot
Modified: 2014-01-03 14:01 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 13:22:26 UTC
CVE-2010-4727 (
  Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags,
  which has unspecified impact and remote attack vectors.

CVE-2010-4726 (
  Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has
  unknown impact and remote attack vectors.  NOTE: this might overlap

CVE-2010-4725 (
  Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags
  option in the php.ini file, which has unspecified impact and remote attack

CVE-2010-4724 (
  Multiple unspecified vulnerabilities in the parser implementation in Smarty
  before 3.0.0 RC3 have unknown impact and remote attack vectors.

CVE-2010-4723 (
  Smarty before 3.0.0, when security is enabled, does not prevent access to
  the (1) dynamic and (2) private object members of an assigned object, which
  has unspecified impact and remote attack vectors.

CVE-2010-4722 (
  Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has
  unknown impact and remote attack vectors.

CVE-2009-5054 (
  Smarty before 3.0.0 beta 4 does not consider the umask value when setting
  the permissions of files, which might allow attackers to bypass intended
  access restrictions via standard filesystem operations.

CVE-2009-5052 (
  Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have
  unknown impact and attack vectors.

Could you please check if our stable branch, 2.6.x, is affected at all? If no, that'd great from our side. If yes, we'd have to stabilize 3.0. Would that be possible?
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 19:59:12 UTC
NVD says 2.6.x is affected, and I'm not sure how many of the bugs got fixes backported in 2.6.27 (NVD doesn't list 2.6.27 as affected, but the pages were last updated in 2011 and .27 came out in 2012). I would strongly suggest stabilizing the 3.* branch. @maintainers: your call.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-12-27 13:45:16 UTC
GLSA vote: no.
Comment 3 Sergey Popov gentoo-dev 2014-01-03 14:01:55 UTC
GLSA vote: no

Closing as noglsa, cleanup will be done in bug #435618