[Git][security-tracker-team/security-tracker][master] Add CVE-2026-62993/smarty
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 21:30:10 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c368831f by Salvatore Bonaccorso at 2026-09-04T22:29:46+02:00
Add CVE-2026-62993/smarty
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3951,7 +3951,12 @@ CVE-2026-67394 (A critical local privilege escalation via OS command injection v
CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote authenti ...)
NOT-FOR-US: cPanel
CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
- TODO: check
+ - smarty4 <unfixed>
+ - smarty3 <unfixed>
+ NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-cq55-c7wv-pxmq
+ NOTE: https://github.com/smarty-php/smarty/pull/1194
+ NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/31e06fc087a8b5a9b236c1e5dacc1c2850a2c115 (v5.8.2)
+ NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90 (v4.5.7)
CVE-2026-61641 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
NOT-FOR-US: Wallos
CVE-2026-61640 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c368831fd720d914952f3307524373ede2b6efd6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c368831fd720d914952f3307524373ede2b6efd6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/2e950cc5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list