USN-5947-1

Source
https://ubuntu.com/security/notices/USN-5947-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5947-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-5947-1
Related
Published
2023-03-13T10:55:33.382499Z
Modified
2023-03-13T10:55:33.382499Z
Summary
php-twig, twig vulnerabilities
Details

Fabien Potencier discovered that Twig was not properly enforcing sandbox policies when dealing with objects automatically cast to strings by PHP. An attacker could possibly use this issue to expose sensitive information. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2019-9942)

Marlon Starkloff discovered that Twig was not properly enforcing closure constraints in some of its array filtering functions. An attacker could possibly use this issue to execute arbitrary code. This issue was only fixed in Ubuntu 20.04 ESM. (CVE-2022-23614)

Dariusz Tytko discovered that Twig was not properly verifying input data utilized when defining pathnames used to access files in a system. An attacker could possibly use this issue to access unauthorized resources and expose sensitive information. (CVE-2022-39261)

References

Affected packages

Ubuntu:Pro:16.04:LTS / twig

Package

Name
twig
Purl
pkg:deb/ubuntu/twig?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.23.1-1ubuntu4+esm1

Affected versions

1.*

1.20.0-1
1.23.1-1ubuntu1
1.23.1-1ubuntu4

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "1.23.1-1ubuntu4+esm1",
            "binary_name": "php-twig"
        },
        {
            "binary_version": "1.23.1-1ubuntu4+esm1",
            "binary_name": "php-twig-doc"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / twig

Package

Name
twig
Purl
pkg:deb/ubuntu/twig?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-1ubuntu0.1~esm1

Affected versions

1.*

1.24.0-2ubuntu1

2.*

2.4.4-2ubuntu1
2.4.6-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "2.4.6-1ubuntu0.1~esm1",
            "binary_name": "php-twig"
        },
        {
            "binary_version": "2.4.6-1ubuntu0.1~esm1",
            "binary_name": "php-twig-doc"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / php-twig

Package

Name
php-twig
Purl
pkg:deb/ubuntu/php-twig?arch=src?distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.5-1ubuntu0.1~esm1

Affected versions

2.*

2.11.3-2
2.12.1-1
2.12.2-1
2.12.3-1
2.12.5-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-cssinliner-extra"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-doc"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-extra-bundle"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-html-extra"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-inky-extra"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-intl-extra"
        },
        {
            "binary_version": "2.12.5-1ubuntu0.1~esm1",
            "binary_name": "php-twig-markdown-extra"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / php-twig

Package

Name
php-twig
Purl
pkg:deb/ubuntu/php-twig?arch=src?distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.8-2ubuntu4+esm1

Affected versions

3.*

3.3.2-1ubuntu3
3.3.4-1
3.3.6-1
3.3.7-1
3.3.8-2ubuntu4

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-cache-extra"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-cssinliner-extra"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-doc"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-extra-bundle"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-html-extra"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-inky-extra"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-intl-extra"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-markdown-extra"
        },
        {
            "binary_version": "3.3.8-2ubuntu4+esm1",
            "binary_name": "php-twig-string-extra"
        }
    ]
}