CVE-2009-5054
Smarty Does Not Consider Umask Values When Setting Permissions
EPSS 0.10%
Description
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.
How to fix CVE-2009-5054
To remediate CVE-2009-5054, upgrade the affected package to a fixed version below.
- Debian/smarty3—upgrade to 3.0~rc1-1 or later
- Packagist/smarty/smarty—upgrade to 3.0.0-beta4 or later
Is CVE-2009-5054 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.0~rc1-1
- from 0, < 3.0.0-beta4