The manufacturer Canonical has not yet set up its devicebase profile. Content such as updates, compatibilities and support may only be maintained with a delay.
Update

USN-7456-1: Twig vulnerabilities

USN-7456-1: Twig vulnerabilities
24 April 2025

Several security issues were fixed in Twig.

Releases

  • Ubuntu 24.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages
php-twig - Flexible, fast, and secure template engine for PHP

Details
Fabien Potencier discovered that Twig did not run sandbox security checks
in some circumstances. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary commands. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-45411)

Jamie Schouten discovered that Twig could bypass the security policy for
an object call. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2024-51754)

Update instructions
The problem can be corrected by updating your system to the following package versions:

Ubuntu 24.04

  • php-twig - 3.8.0-2ubuntu0.1~esm1
    Ubuntu 22.04
    php-twig - 3.3.8-2ubuntu4+esm2
    Ubuntu 20.04
  • php-twig - 2.12.5-1ubuntu0.1~esm2
    In general, a standard system update will make all the necessary changes.
Version: 24.04 LTS Link
Receive Important Update Messages Stay tuned for upcoming Canonical Ubuntu Server updates

More from the Operating Systems section

Was the content helpful to you?

Advertisement Advertise here?
Udemy IT certification ad