CVE-2010-4723: Critical severity smarty vulnerability
Published Feb 3, 2011
·Updated
Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.
Affected Software
70 affected components
Smarty smarty=1.4.3
Smarty smarty=1.0
Smarty smarty=1.0b
Smarty smarty=2.3.1
Smarty smarty=3.0.0-beta6
Smarty smarty=2.6.0-rc3
Smarty smarty=2.6.25
Smarty smarty=3.0.0-beta8
Smarty smarty=1.4.0
Smarty smarty=1.4.5
Smarty smarty=2.6.1
Smarty smarty=2.6.7
Smarty smarty=2.6.20
Smarty smarty=2.3.0
Smarty smarty=1.0a
Smarty smarty=1.1.0
Smarty smarty<=3.0.0
Smarty smarty=1.4.0-b2
Smarty smarty=2.6.0
Smarty smarty=2.6.15
Smarty smarty=2.6.3
Smarty smarty=3.0.0-rc2
Smarty smarty=2.6.14
Smarty smarty=2.5.0-rc1
Smarty smarty=1.2.1
Smarty smarty=2.6.17
Smarty smarty=2.6.11
Smarty smarty=2.6.0-rc2
Smarty smarty=3.0.0-rc3
Smarty smarty=3.0.0-beta7
Smarty smarty=1.3.0
Smarty smarty=1.4.1
Smarty smarty=2.5.0-rc2
Smarty smarty=2.0.1
Smarty smarty=2.5.0
Smarty smarty=1.4.2
Smarty smarty=1.5.0
Smarty smarty=2.1.0
Smarty smarty=2.6.22
Smarty smarty=1.5.2
Smarty smarty=2.6.12
Smarty smarty=2.6.18
Smarty smarty=1.5.1
Smarty smarty=2.0.0
Smarty smarty=2.4.1
Smarty smarty=2.6.6
Smarty smarty=2.6.26
Smarty smarty=2.6.16
Smarty smarty=2.6.9
Smarty smarty=1.2.2
Smarty smarty=3.0.0-beta5
Smarty smarty=2.6.0-rc1
Smarty smarty=2.6.24
Smarty smarty=2.1.1
Smarty smarty=2.6.4
Smarty smarty=2.2.0
Smarty smarty=2.4.2
Smarty smarty=2.6.10
Smarty smarty=2.6.2
Smarty smarty=1.4.0-b1
Smarty smarty=2.6.13
Smarty smarty=3.0.0-beta4
Smarty smarty=2.6.5
Smarty smarty=1.3.2
Smarty smarty=2.4.0
Smarty smarty=1.3.1
Smarty smarty=1.4.4
Smarty smarty=1.4.6
Smarty smarty=1.2.0
Smarty smarty=3.0.0-rc1
Event History
Feb 3, 2011
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4723?
The severity of CVE-2010-4723 is categorized as medium due to its potential impact on security when improper access to object members occurs.
2
How do I fix CVE-2010-4723?
To fix CVE-2010-4723, upgrade Smarty to version 3.0.0 or later, where the vulnerability has been addressed.
3
What versions are affected by CVE-2010-4723?
CVE-2010-4723 affects Smarty versions prior to 3.0.0, including 1.0 through 2.6.26.
4
What impact does CVE-2010-4723 have?
CVE-2010-4723 may allow unauthorized access to dynamic and private object members, posing risks of information disclosure.
5
Is CVE-2010-4723 a remote attack vector?
Yes, CVE-2010-4723 can potentially be exploited through remote attack vectors.