UbuntuUpdates.org

Package "php-twig"

Name: php-twig

Description:

Flexible, fast, and secure template engine for PHP

Latest version: 3.8.0-2ubuntu1
Release: noble (24.04)
Level: updates
Repository: universe
Homepage: https://twig.symfony.com

Links


Download "php-twig"


Other versions of "php-twig" in Noble

Repository Area Version
base universe 3.8.0-2
security universe 3.8.0-2ubuntu1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.8.0-2ubuntu1 2025-05-22 22:07:22 UTC

  php-twig (3.8.0-2ubuntu1) noble-security; urgency=medium

  * SECURITY UPDATE: sandbox restriction bypass
    - 0003-Fix-a-security-issue-when-an-included-sandboxed-temp.patch:
      prevent bypass
    - CVE-2024-45411

 -- Julia Sarris <email address hidden> Wed, 21 May 2025 17:08:32 +0200

CVE-2024-45411 Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to byp



About   -   Send Feedback to @ubuntu_updates