Описание
TYPO3 Image Processing susceptible to Code Execution
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 is susceptible to remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
For a successful exploit, the GhostScript binary gs must be available on the server system.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-11832
- https://github.com/github/advisory-database/pull/3530
- https://github.com/TYPO3/typo3/commit/2c04eeac44733fda491f92c697f88c1337d19c79
- https://github.com/TYPO3/typo3/commit/51fdb774a57ee30e8d60c0e33b4a0b92d775739e
- https://github.com/TYPO3/typo3/commit/e845d90b82b2f72ab12a9e37f15082297832beca
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2019-11832.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2019-11832.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2019-012
Пакеты
Наименование
typo3/cms-core
composer
Затронутые версииВерсия исправления
>= 8.0.0, < 8.7.25
8.7.25
Наименование
typo3/cms-core
composer
Затронутые версииВерсия исправления
>= 9.0.0, < 9.5.6
9.5.6
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 8.0.0, < 8.7.25
8.7.25
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 9.0.0, < 9.5.6
9.5.6
Связанные уязвимости
CVSS3: 7.5
nvd
больше 6 лет назад
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.