Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-5054

Опубликовано: 03 фев. 2011
Источник: ubuntu
Приоритет: low
CVSS2: 7.5

Описание

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

ignored

end of life
karmic

not-affected

uses system smarty
lucid

not-affected

uses system smarty
maverick

not-affected

uses system smarty
natty

not-affected

uses system smarty
oneiric

not-affected

uses system smarty
precise

not-affected

uses system smarty

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

uses system smarty
esm-apps/xenial

not-affected

uses system smarty
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [uses system smarty]]
hardy

ignored

end of life
karmic

not-affected

uses system smarty
lucid

not-affected

uses system smarty
maverick

not-affected

uses system smarty
natty

not-affected

uses system smarty
oneiric

not-affected

uses system smarty

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

debian
почти 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when sett ...

github
больше 3 лет назад

Smarty Does Not Consider Umask Values When Setting Permissions

7.5 High

CVSS2