There is a file disclosure vulnerability in SMF (Simple Machines …
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.
References
- http://www.openwall.com/lists/oss-security/2013/02/01/4 x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2013/02/01/4 x_refsource_MISC x_transferred
- http://www.openwall.com/lists/oss-security/2013/02/01/4 x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2013/02/01/4 x_refsource_MISC x_transferred
Affected products
- ==through 2.0.3
Matching in nixpkgs
pkgs.smfh
Sleek Manifest File Handler
pkgs.asmfmt
Go assembler formatter
pkgs.libsmf
C library for reading and writing Standard MIDI Files
pkgs.nasmfmt
Formatter for NASM source files
-
nixos-unstable 2022-09-15
- nixpkgs-unstable 2022-09-15
- nixos-unstable-small 2022-09-15
-
nixos-25.11 2022-09-15
- nixos-25.11-small 2022-09-15
- nixpkgs-25.11-darwin 2022-09-15
pkgs.mt32emu-smf2wav
Produces a WAVE file from a Standard MIDI file (SMF)
-
nixos-unstable smf2wav-1.9.0
- nixpkgs-unstable smf2wav-1.9.0
- nixos-unstable-small smf2wav-1.9.0
-
nixos-25.11 smf2wav-1.9.0
- nixos-25.11-small smf2wav-1.9.0
- nixpkgs-25.11-darwin smf2wav-1.9.0
pkgs.python312Packages.pysmf
Python extension module for reading and writing Standard MIDI Files, based on libsmf
pkgs.python313Packages.pysmf
Python extension module for reading and writing Standard MIDI Files, based on libsmf
pkgs.python314Packages.pysmf
Python extension module for reading and writing Standard MIDI Files, based on libsmf
pkgs.tests.fetchFromGitHub.rootDir
None
-
nixos-unstable smfyc8dzpa0l
- nixpkgs-unstable smfyc8dzpa0l
- nixos-unstable-small smfyc8dzpa0l
Package maintainers
-
@kalbasit Wael Nasreddine <wael.nasreddine@gmail.com>
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@eclairevoyant éclairevoyant
-
@Gerg-L Greg Leyda <gregleyda@proton.me>
-
@NotAShelf NotAShelf <raf@notashelf.dev>