Articles / Debian: Security update for…

Debian: Security update for TYPO3

Several vulnerabilities were discovered in TYPO3, a content management system. An insecure call to unserialize in the help system enables arbitrary code execution by authenticated users. The TYPO3 backend contains several cross-site scripting vulnerabilities.

Authenticated users who can access the configuration module can obtain the encryption key, allowing them to escalate their privileges. The RemoveXSS HTML sanitizer did not remove several HTML5 JavaScript, thus failing to mitigate the impact of cross-site scripting vulnerabilities.

Updated packages are available from security.debian.org.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2537-1                   security@debian.org
http://www.debian.org/security/                            Florian Weimer
August 30, 2012                        http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : typo3-src
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2012-3527 CVE-2012-3528 CVE-2012-3529 CVE-2012-3530
                CVE-2012-3531

Several vulnerabilities were discovered in TYPO3, a content management
system.

CVE-2012-3527
  An insecure call to unserialize in the help system enables
  arbitrary code execution by authenticated users.

CVE-2012-3528
  The TYPO3 backend contains several cross-site scripting
  vulnerabilities.

CVE-2012-3529
  Authenticated users who can access the configuration module
  can obtain the encryption key, allowing them to escalate their
  privileges.

CVE-2012-3530
  The RemoveXSS HTML sanitizer did not remove several HTML5
  JavaScript, thus failing to mitigate the impact of cross-site
  scripting vulnerabilities.

For the stable distribution (squeeze), these problems have been fixed
in version 4.3.9+dfsg1-1+squeeze5.

For the testing distribution (wheezy) and the unstable distribution
(sid), these problems have been fixed in version 4.5.19+dfsg1-1.

We recommend that you upgrade your typo3-src packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJQP8gcAAoJEL97/wQC1SS+ic0H/RUakdYXR9ym8GacNG8q87cC
O5eABopjcLRURua5FLngzCIaYQwSfR247Pn8AnL1WkxZlxj8zqu8mq0+ZJX07kCR
Tote3E3iKfe5zx0MWUXy2qHumKDN6B3sMTtyFjtpsAugKXgYJHCbqHmJT9heFH0P
lzmLlaScEiCvKpFOfK6fuuXbMUS/wAry4pPi3GArrwNi0HeqZGBH2lfclqAGQG04
LbygNK8+N51DQWrc5RBvdrXky7XbAq1bCO2tH7SLw9nfNZ9MgwoAqbZrl8C0GEzz
fDlTEZBWWhBnLtIexy22ZSFCDT97g8LpeCtQJini8BK+a4mu+LHDZbUBu+T9KTE=
=Wapq
-----END PGP SIGNATURE-----
Screenshot

Project Spotlight

Kigo Video Converter Ultimate for Mac

A tool for converting and editing videos.

Screenshot

Project Spotlight

Kid3

An efficient tagger for MP3, Ogg/Vorbis, and FLAC files.