CVE-2010-4724: Critical severity smarty vulnerability
Published Feb 3, 2011
·Updated
Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.
Affected Software
68 affected components
Smarty smarty=1.4.3
Smarty smarty=1.0
Smarty smarty=1.0b
Smarty smarty=2.3.1
Smarty smarty=3.0.0-beta6
Smarty smarty=2.6.0-rc3
Smarty smarty=2.6.25
Smarty smarty=3.0.0-beta8
Smarty smarty=1.4.0
Smarty smarty=1.4.5
Smarty smarty=2.6.1
Smarty smarty=2.6.7
Smarty smarty=2.6.20
Smarty smarty=2.3.0
Smarty smarty=1.0a
Smarty smarty=1.1.0
Smarty smarty=1.4.0-b2
Smarty smarty=2.6.0
Smarty smarty=2.6.15
Smarty smarty=2.6.3
Smarty smarty=2.6.14
Smarty smarty=2.5.0-rc1
Smarty smarty=1.2.1
Smarty smarty=2.6.17
Smarty smarty=2.6.11
Smarty smarty=2.6.0-rc2
Smarty smarty=3.0.0-beta7
Smarty smarty=1.3.0
Smarty smarty=1.4.1
Smarty smarty=2.5.0-rc2
Smarty smarty=2.0.1
Smarty smarty=2.5.0
Smarty smarty=1.4.2
Smarty smarty=1.5.0
Smarty smarty=2.1.0
Smarty smarty=2.6.22
Smarty smarty=1.5.2
Smarty smarty=2.6.12
Smarty smarty=2.6.18
Smarty smarty=1.5.1
Smarty smarty=2.0.0
Smarty smarty=2.4.1
Smarty smarty=2.6.6
Smarty smarty=2.6.26
Smarty smarty=2.6.16
Smarty smarty=2.6.9
Smarty smarty=1.2.2
Smarty smarty=3.0.0-beta5
Smarty smarty=2.6.0-rc1
Smarty smarty=2.6.24
Smarty smarty=2.1.1
Smarty smarty=2.6.4
Smarty smarty=2.2.0
Smarty smarty=2.4.2
Smarty smarty=2.6.10
Smarty smarty=2.6.2
Smarty smarty=1.4.0-b1
Smarty smarty=2.6.13
Smarty smarty=3.0.0-beta4
Smarty smarty=2.6.5
Smarty smarty=1.3.2
Smarty smarty=2.4.0
Smarty smarty=1.3.1
Smarty smarty<=3.0.0
Smarty smarty=1.4.4
Smarty smarty=1.4.6
Smarty smarty=1.2.0
Smarty smarty=3.0.0-rc1
Event History
Feb 3, 2011
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4724?
The severity of CVE-2010-4724 is not explicitly defined, but it involves multiple unspecified vulnerabilities which could potentially lead to remote attacks.
2
How do I fix CVE-2010-4724?
To fix CVE-2010-4724, upgrade to a version of Smarty newer than 3.0.0 RC3.
3
What software versions are affected by CVE-2010-4724?
CVE-2010-4724 affects multiple Smarty versions, including versions from 1.0 up to 3.0.0 beta series.
4
What types of attacks are possible due to CVE-2010-4724?
CVE-2010-4724 has unknown attack vectors, indicating potential for remote exploitation due to unspecified vulnerabilities.
5
Is CVE-2010-4724 still a concern today?
While CVE-2010-4724 was reported over a decade ago, systems running vulnerable versions should still be updated to mitigate any ongoing risks.