Lucene search

K
mageiaGentoo FoundationMGASA-2023-0155
HistoryApr 24, 2023 - 3:20 a.m.

Updated php-smarty packages fix security vulnerability

2023-04-2403:20:26
Gentoo Foundation
advisories.mageia.org
21
php-smarty security vulnerability javascript cve-2023-28447 bug fixes release notes unix

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

EPSS

0.002

Percentile

52.7%

Cross site scripting vulnerability in Javascript escaping. (CVE-2023-28447) Additional bug fixes included. See referenced release notes for details.

OSVersionArchitecturePackageVersionFilename
Mageia8noarchphp-smarty< 4.3.1-1php-smarty-4.3.1-1.mga8

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

EPSS

0.002

Percentile

52.7%