Fedora 28 : php-Smarty2 (2018-2d2739ebed)

high Nessus Plugin ID 120320

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

2017-11-03

- replace functions deprecated in PHP 7.2

2016-09-11 Uwe Tews

- {math} fix parameter checking order to avoid misleading message

- {math} replace wrong versiom

2016-07-19 Uwe Tews

- {math} shell injection vulnerability patch provided by Tim Weber

2015-12-30 Uwe Tews

- fixed plugin filepath cache must not be static, because of possible problem when using multiple Smarty instances with diffrent plugins_dir settings https://github.com/smarty-php/smarty/issues/146

2015-06-21 Uwe Tews

- PHP7 raises E_DEPRECATED use __construct for compatibility

2013-09-30

- Fixed old vulnerability bug https://bugs.gentoo.org/show_bug.cgi?id=356615

2013-07-16 Uwe Tews

- Fixed made Smarty_Compiler.class.php compatible with PHP 5.5

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php-Smarty2 package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2018-2d2739ebed

https://github.com/smarty-php/smarty/issues/146

Plugin Details

Severity: High

ID: 120320

File Name: fedora_2018-2d2739ebed.nasl

Version: 1.4

Type: local

Agent: unix

Published: 1/3/2019

Updated: 1/6/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:28, p-cpe:/a:fedoraproject:fedora:php-smarty2

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 12/3/2018

Vulnerability Publication Date: 12/3/2018

Reference Information