Описание
TYPO3 is vulnerable to Insecure randomness in uniqid function
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-3666
- https://github.com/TYPO3/typo3/commit/302b35e714ca30ddb71ab36b9cbb2bea760a2f0e
- https://github.com/TYPO3/typo3/commit/352d6066bf09137e86705bc060fd4ab3ba8f9191
- https://github.com/TYPO3/typo3/commit/42324b30546b1e49fb16c916fc71cceb99ad9fd0
- https://github.com/TYPO3/typo3/commit/f6d2e33cfab87c9e44eca275d6755be747e3cd7e
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719
- https://security-tracker.debian.org/tracker/CVE-2010-3666
- https://typo3.org/security/advisory/typo3-sa-2010-012/#Insecure_Randomness
Пакеты
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
< 4.1.14
4.1.14
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
>= 4.2.0, < 4.2.13
4.2.13
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
>= 4.3.0, < 4.3.4
4.3.4
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
>= 4.4.0, < 4.4.1
4.4.1
Связанные уязвимости
CVSS3: 5.3
ubuntu
почти 7 лет назад
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
CVSS3: 5.3
nvd
почти 7 лет назад
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
CVSS3: 5.3
debian
почти 7 лет назад
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x ...