Описание
Typo3 Host Header Spoofing Vulnerability
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-3941
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2014-3941.yaml
- https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00037.html
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00083.html
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001
- http://www.debian.org/security/2014/dsa-2942
- http://www.openwall.com/lists/oss-security/2014/06/03/2
Пакеты
typo3/cms
>= 4.5.0, <= 4.5.33
4.5.34
typo3/cms
>= 4.7.0, <= 4.7.18
4.7.19
typo3/cms
>= 6.0.0, <= 6.0.13
6.0.14
typo3/cms
>= 6.1.0, <= 6.1.8
6.1.9
typo3/cms
>= 6.2.0, < 6.2.3
6.2.3
Связанные уязвимости
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6 ...