CIVI-SA-2017-09 Shell Injection Vulerabilty in Smarty

Publicat
2017-11-01 09:00
Written by

As part of CiviCRM's defense in depth program, we have upgraded Smarty following an announcement by them that one of the functions in the Smarty templating engine potentially allowed for shell injection.

Despite this vulnerability in the Smarty library, CiviCRM's usage of Smarty appears to prevent such shell injection vulnerabilities.

Security Risk
Not Critical
Vulnerability
Other
Affected Versions

CiviCRM Versions prior to 4.7.26 and 4.6.33

Fixed Versions

CiviCRM Version 4.7.26 and 4.6.33

Solutions

Upgrade CiviCRM to the latest version

  • 4.7.26
  • 4.6.33

or later

Or apply the following patch 

 

Credits

Seamus Lee of Australian Greens for reporting and Fixing the issue

References