[Git][security-tracker-team/security-tracker][master] Add two new smarty issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 20:25:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8889c178 by Salvatore Bonaccorso at 2026-08-16T21:25:34+02:00
Add two new smarty issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13297,9 +13297,17 @@ CVE-2026-64637 (Improper privilege management in the XML-RPC API of Plesk before
CVE-2026-64636 (An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Lin ...)
NOT-FOR-US: Plesk
CVE-2026-62996 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
- TODO: check
+ - smarty4 <not-affected> (Vulnerable code not present)
+ - smarty3 <not-affected> (Vulnerable code not present)
+ NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-rjhh-76wf-8xmw
+ NOTE: https://github.com/smarty-php/smarty/pull/1195
+ NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e (v5.8.4)
CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
- TODO: check
+ - smarty4 <unfixed>
+ - smarty3 <unfixed>
+ NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-f6wf-28g6-769x
+ NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/99c048ce7a590c519b79fbd38ad0143a08183a1f (v5.8.2)
+ NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90 (v4.5.7)
CVE-2026-56794 (Dell OpenManage Server Administrator, versions prior to 11.1.0.2, cont ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56793 (Dell OpenManage Server Administrator, versions prior to 11.1.0.2, cont ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8889c17894e6d6e03bacc546109c7fbcc28e5cb6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8889c17894e6d6e03bacc546109c7fbcc28e5cb6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/979058de/attachment.htm>
More information about the debian-security-tracker-commits
mailing list