• [SECURITY] [DSA 4419-1] twig security update

    From Sebastien Delafond@1:229/2 to All on Fri Mar 29 17:00:02 2019
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4419-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    March 29, 2019 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : twig
    CVE ID : CVE-2019-9942

    Fabien Potencier discovered that twig, a template engine for PHP, did
    not correctly enforce sandboxing. This could result in potential
    information disclosure.

    For the stable distribution (stretch), this problem has been fixed in
    version 1.24.0-2+deb9u1.

    We recommend that you upgrade your twig packages.

    For the detailed security status of twig please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/twig

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlyePeQACgkQEL6Jg/PV nWTO4AgArUWM+AF5HOWtip3WmdM6X416ddkT2Hh6OMrolzDbdC2uhOn/fNWvKIQv sOyacxNdy4Ha/ZvjmLWizEco15m4sI3xF99kJuem+gwmYDj0x0DmRNN2XVRWzXzx qfgaynRaXkT+gYYtPWwa7wCvvlLDEE5D2CkFZZkjsR2tsdWdRpvbKUfTnEYN4iz6 B7k1KsH+1aAJSZwQj7m5lNrtjxc/M3GueRF6WkQ+sIscXO8xd+VLEzAO8osSV0M+ 8O0me0m31+04lU5t89+bRQzqoZRQ2cJtWYx8a+nvD5+v5xx6b4ZB5qTj6VBGFNPu tHJ10cBUkFaYsd8wZren2LGWRI++zA==
    =qMcF
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)