CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates
Bug #202422 reported by
Emanuele Gentili
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
gallery2 (Debian) |
Fix Released
|
Unknown
|
|||
gallery2 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Won't Fix
|
Undecided
|
Unassigned | ||
Edgy |
Won't Fix
|
Undecided
|
Unassigned | ||
Feisty |
Won't Fix
|
Undecided
|
Unassigned | ||
Gutsy |
Won't Fix
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned | ||
smarty (Debian) |
Fix Released
|
Unknown
|
|||
smarty (Ubuntu) |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Dapper |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Edgy |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Feisty |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Gutsy |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Hardy |
Fix Released
|
Medium
|
Emanuele Gentili |
Bug Description
The modifier.
http://
http://
Changed in smarty: | |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in smarty: | |
status: | Confirmed → In Progress |
Changed in smarty: | |
status: | Unknown → New |
Changed in smarty: | |
status: | New → Fix Released |
Changed in smarty: | |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | New → In Progress |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | New → In Progress |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | New → In Progress |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in smarty: | |
status: | Fix Committed → Fix Released |
Changed in gallery2: | |
status: | Unknown → New |
Changed in gallery2: | |
status: | New → Fix Released |
Changed in gallery2 (Ubuntu Dapper): | |
status: | New → Won't Fix |
To post a comment you must log in.
Uploaded, thanks ;)