USN-5947-1

Source
https://ubuntu.com/security/notices/USN-5947-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5947-1.json
Related
Published
2023-03-13T10:55:33.382499Z
Modified
2023-03-13T10:55:33.382499Z
Summary
php-twig, twig vulnerabilities
Details

Fabien Potencier discovered that Twig was not properly enforcing sandbox policies when dealing with objects automatically cast to strings by PHP. An attacker could possibly use this issue to expose sensitive information. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2019-9942)

Marlon Starkloff discovered that Twig was not properly enforcing closure constraints in some of its array filtering functions. An attacker could possibly use this issue to execute arbitrary code. This issue was only fixed in Ubuntu 20.04 ESM. (CVE-2022-23614)

Dariusz Tytko discovered that Twig was not properly verifying input data utilized when defining pathnames used to access files in a system. An attacker could possibly use this issue to access unauthorized resources and expose sensitive information. (CVE-2022-39261)

References

Affected packages

Ubuntu:Pro:22.04:LTS / php-twig

Package

Name
php-twig

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
3.3.8-2ubuntu4+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "php-twig-string-extra": "3.3.8-2ubuntu4+esm1",
            "php-twig-cache-extra": "3.3.8-2ubuntu4+esm1",
            "php-twig-markdown-extra": "3.3.8-2ubuntu4+esm1",
            "php-twig-extra-bundle": "3.3.8-2ubuntu4+esm1",
            "php-twig-html-extra": "3.3.8-2ubuntu4+esm1",
            "php-twig-inky-extra": "3.3.8-2ubuntu4+esm1",
            "php-twig-doc": "3.3.8-2ubuntu4+esm1",
            "php-twig-cssinliner-extra": "3.3.8-2ubuntu4+esm1",
            "php-twig": "3.3.8-2ubuntu4+esm1",
            "php-twig-intl-extra": "3.3.8-2ubuntu4+esm1"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / twig

Package

Name
twig

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
2.4.6-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "php-twig-doc": "2.4.6-1ubuntu0.1~esm1",
            "php-twig": "2.4.6-1ubuntu0.1~esm1"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / php-twig

Package

Name
php-twig

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
2.12.5-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "php-twig-markdown-extra": "2.12.5-1ubuntu0.1~esm1",
            "php-twig-extra-bundle": "2.12.5-1ubuntu0.1~esm1",
            "php-twig-html-extra": "2.12.5-1ubuntu0.1~esm1",
            "php-twig-inky-extra": "2.12.5-1ubuntu0.1~esm1",
            "php-twig-doc": "2.12.5-1ubuntu0.1~esm1",
            "php-twig-cssinliner-extra": "2.12.5-1ubuntu0.1~esm1",
            "php-twig": "2.12.5-1ubuntu0.1~esm1",
            "php-twig-intl-extra": "2.12.5-1ubuntu0.1~esm1"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / twig

Package

Name
twig

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.23.1-1ubuntu4+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "php-twig-doc": "1.23.1-1ubuntu4+esm1",
            "php-twig": "1.23.1-1ubuntu4+esm1"
        }
    ]
}