CVE-2010-4725
EPSS 0.43%
Description
Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote attack vectors.
How to fix CVE-2010-4725
To remediate CVE-2010-4725, upgrade the affected package to a fixed version below.
- Debian/smarty3—upgrade to 3.0.8-1 or later
Is CVE-2010-4725 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.0.8-1