Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4726 to the following vulnerability: Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4726 [2] http://smarty-php.googlecode.com/svn/trunk/distribution/change_log.txt
Relevant Smarty Changelog [2] entry: ===== RC1 ===== .. 17/04/2010 - security fix in {math} plugin and related SVN log record: r3555 | Uwe.Tews | 2010-04-17 12:24:44 +0200 (Sat, 17 Apr 2010) | 2 lines - security fix in {math} plugin
Created attachment 530103 [details] Smarty r3555 SVN repository upstream patch
This issue affects the versions of the php-Smarty package, as shipped with Fedora release of 14 and 15. Please schedule an update. -- This issue affects the versions of the php-Smarty package, as present within Fedora EPEL 5 and Fedora EPEL 6 repositories. Please schedule an update.
Created php-Smarty tracking bugs for this issue Affects: fedora-all [bug 748909] Affects: epel-6 [bug 748910] Affects: epel-5 [bug 748911]
I have a patched version ready, waiting on resolution to 748773.