CVE-2024-35226

Publication date 28 May 2024

Last updated 12 December 2024


Ubuntu priority

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

Status

Package Ubuntu Release Status
smarty3 24.10 oracular
Fixed 3.1.48-1ubuntu0.24.10.1
24.04 LTS noble
Fixed 3.1.48-1ubuntu0.24.04.1
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Fixed 3.1.39-2ubuntu1.22.04.2
20.04 LTS focal
Fixed 3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1
18.04 LTS bionic
16.04 LTS xenial
Needs evaluation
smarty4 24.10 oracular
Needs evaluation
24.04 LTS noble
Needs evaluation
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy Not in release
20.04 LTS focal Not in release

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro