Описание
TYPO3 is vulnerable to Insecure randomness in uniqid function
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-3666
- https://github.com/TYPO3/typo3/commit/302b35e714ca30ddb71ab36b9cbb2bea760a2f0e
- https://github.com/TYPO3/typo3/commit/352d6066bf09137e86705bc060fd4ab3ba8f9191
- https://github.com/TYPO3/typo3/commit/42324b30546b1e49fb16c916fc71cceb99ad9fd0
- https://github.com/TYPO3/typo3/commit/f6d2e33cfab87c9e44eca275d6755be747e3cd7e
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719
- https://security-tracker.debian.org/tracker/CVE-2010-3666
- https://typo3.org/security/advisory/typo3-sa-2010-012/#Insecure_Randomness
Пакеты
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
< 4.1.14
4.1.14
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
>= 4.2.0, < 4.2.13
4.2.13
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
>= 4.3.0, < 4.3.4
4.3.4
Наименование
typo3/cms-install
composer
Затронутые версииВерсия исправления
>= 4.4.0, < 4.4.1
4.4.1
Связанные уязвимости
CVSS3: 5.3
ubuntu
больше 6 лет назад
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
CVSS3: 5.3
nvd
больше 6 лет назад
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
CVSS3: 5.3
debian
больше 6 лет назад
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x ...