Path traversal in Smarty - CVE-2018-13982
Published: March 28, 2022
Vulnerability identifier: #VU61666
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-13982
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Smarty_Security::isTrustedResourceDir(). A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Smarty
Fedora
Ubuntu
smarty3 (Ubuntu package)
php-Smarty
Fedora
Ubuntu
smarty3 (Ubuntu package)
php-Smarty
How to mitigate CVE-2018-13982
Install update from vendor's website.
Smarty - update to 3.1.33
smarty3 (Ubuntu package) - addressed in versions 3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1, 3.1.39-2ubuntu0.21.10.1
php-Smarty - addressed in versions 3.1.33-1.el7, 3.1.33-1.fc28, 3.1.33-1.fc29
smarty3 (Ubuntu package) - addressed in versions 3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1, 3.1.39-2ubuntu0.21.10.1
php-Smarty - addressed in versions 3.1.33-1.el7, 3.1.33-1.fc28, 3.1.33-1.fc29
External References
- https://github.com/smarty-php/smarty/commit/f9ca3c63d1250bb56b2bda609dcc9dd81f0065f8
- https://github.com/smarty-php/smarty/commit/c9dbe1d08c081912d02bd851d1d1b6388f6133d1
- https://github.com/smarty-php/smarty/commit/bcedfd6b58bed4a7366336979ebaa5a240581531
- https://github.com/smarty-php/smarty/commit/8d21f38dc35c4cd6b31c2f23fc9b8e5adbc56dfe
- https://github.com/smarty-php/smarty/commit/2e081a51b1effddb23f87952959139ac62654d50
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180420-01_Smarty_Path_Traversal
- https://lists.debian.org/debian-lts-announce/2021/04/msg00004.html
- https://lists.debian.org/debian-lts-announce/2021/04/msg00014.html
- https://lists.debian.org/debian-lts-announce/2021/10/msg00015.html