USN-5983-1: Nette vulnerability
29 March 2023
Nette could be made to run programs if it received specially crafted network traffic.
Releases
Packages
- php-nette - Nette Framework
Details
Cyku Hong discovered that Nette was not properly handling and validating
data used for code generation. A remote attacker could possibly use this
issue to execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
Ubuntu 16.04
-
php-nette
-
2.3.8-1ubuntu1+esm1
Available with Ubuntu Pro
After a standard system update you need to restart any applications using
Nette to make all the necessary changes.