[Git][security-tracker-team/security-tracker][master] Add two new smarty issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 16 20:25:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8889c178 by Salvatore Bonaccorso at 2026-08-16T21:25:34+02:00
Add two new smarty issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13297,9 +13297,17 @@ CVE-2026-64637 (Improper privilege management in the XML-RPC API of Plesk before
 CVE-2026-64636 (An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Lin ...)
 	NOT-FOR-US: Plesk
 CVE-2026-62996 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
-	TODO: check
+	- smarty4 <not-affected> (Vulnerable code not present)
+	- smarty3 <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-rjhh-76wf-8xmw
+	NOTE: https://github.com/smarty-php/smarty/pull/1195
+	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e (v5.8.4)
 CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
-	TODO: check
+	- smarty4 <unfixed>
+	- smarty3 <unfixed>
+	NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-f6wf-28g6-769x
+	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/99c048ce7a590c519b79fbd38ad0143a08183a1f (v5.8.2)
+	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90 (v4.5.7)
 CVE-2026-56794 (Dell OpenManage Server Administrator, versions prior to 11.1.0.2, cont ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-56793 (Dell OpenManage Server Administrator, versions prior to 11.1.0.2, cont ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8889c17894e6d6e03bacc546109c7fbcc28e5cb6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8889c17894e6d6e03bacc546109c7fbcc28e5cb6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/979058de/attachment.htm>


More information about the debian-security-tracker-commits mailing list