Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title typo3-src security update
Informations
Name DSA-2537 First vendor Publication 2012-08-30
Vendor Debian Last vendor Modification 2012-08-30
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:S/C:P/I:P/A:P)
Cvss Base Score 4.6 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity High
Cvss Expoit Score 3.9 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities were discovered in TYPO3, a content management system.

CVE-2012-3527 An insecure call to unserialize in the help system enables arbitrary code execution by authenticated users.

CVE-2012-3528 The TYPO3 backend contains several cross-site scripting vulnerabilities.

CVE-2012-3529 Authenticated users who can access the configuration module can obtain the encryption key, allowing them to escalate their privileges.

CVE-2012-3530 The RemoveXSS HTML sanitizer did not remove several HTML5 JavaScript, thus failing to mitigate the impact of cross-site scripting vulnerabilities.

For the stable distribution (squeeze), these problems have been fixed in version 4.3.9+dfsg1-1+squeeze5.

For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 4.5.19+dfsg1-1.

We recommend that you upgrade your typo3-src packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2537

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)
25 % CWE-502 Deserialization of Untrusted Data
25 % CWE-200 Information Exposure

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:19962
 
Oval ID: oval:org.mitre.oval:def:19962
Title: DSA-2537-1 typo3-src - several
Description: Several vulnerabilities were discovered in TYPO3, a content management system.
Family: unix Class: patch
Reference(s): DSA-2537-1
CVE-2012-3527
CVE-2012-3528
CVE-2012-3529
CVE-2012-3530
CVE-2012-3531
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): typo3-src
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 178
Os 2

OpenVAS Exploits

Date Description
2012-09-07 Name : Debian Security Advisory DSA 2537-1 (typo3-src)
File : nvt/deb_2537_1.nasl

Nessus® Vulnerability Scanner

Date Description
2012-08-31 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2537.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:31:19
  • Multiple Updates