Описание
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.26 (включая)
Одно из
cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.0a:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.0b:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.0:b1:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.0:b2:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.5.0:rc2:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.0:rc2:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.0:rc3:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.5:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.6:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.7:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.9:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.10:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.11:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.12:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.13:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.14:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.15:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.16:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.17:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.18:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.20:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.22:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.24:*:*:*:*:*:*:*
cpe:2.3:a:smarty:smarty:2.6.25:*:*:*:*:*:*:*
EPSS
Процентиль: 23%
0.00077
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
ubuntu
почти 15 лет назад
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.
debian
почти 15 лет назад
Smarty before 3.0.0 beta 4 does not consider the umask value when sett ...
github
больше 3 лет назад
Smarty Does Not Consider Umask Values When Setting Permissions
EPSS
Процентиль: 23%
0.00077
Низкий
7.5 High
CVSS2
Дефекты
CWE-264