{"id":"GHSA-6m9f-8vwq-97pm","summary":"Smarty Does Not Consider Umask Values When Setting Permissions","details":"Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.","aliases":["CVE-2009-5054"],"modified":"2024-12-04T05:40:47.032547Z","published":"2022-05-02T04:00:47Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-08T22:08:36Z","nvd_published_at":"2011-02-03T17:00:00Z","cwe_ids":["CWE-281"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-5054"},{"type":"PACKAGE","url":"https://github.com/smarty-php/smarty"},{"type":"WEB","url":"https://web.archive.org/web/20101116174040/http://smarty-php.googlecode.com/svn/trunk/distribution/change_log.txt"}],"affected":[{"package":{"name":"smarty/smarty","ecosystem":"Packagist","purl":"pkg:composer/smarty/smarty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.0-beta4"}]}],"versions":["v2.6.24","v2.6.25","v2.6.26","v2.6.27","v2.6.28","v2.6.29","v2.6.30","v2.6.31","v2.6.33"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6m9f-8vwq-97pm/GHSA-6m9f-8vwq-97pm.json"}}],"schema_version":"1.9.0"}