It was discovered that Smarty did not properly sanitize template file names. An attacker could possibly use this issue to cause Smarty to crash, resulting in a denial of service, or possibly execute arbitrary code.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.3.1-1ubuntu0.24.10.1", "binary_name": "smarty4" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.3.1-1ubuntu0.24.04.1", "binary_name": "smarty4" } ] }