漏洞信息详情
TYPO3 Internal Form Engine 'class.t3lib_formmail.php'输入验证漏洞
漏洞简介
TYPO3 4.0.5之前版本,4.1beta和4.1RC1的class.t3lib_formmail.php中的开始函数可被攻击者利用,注入任意的电子邮件头。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
Typo3 Typo3 3.8
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 4.0
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 3.5 b5
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 3.5 .0
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 3.6.2
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 3.7 .0
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 4.0.1
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 4.0.2
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 4.0.3
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
Typo3 Typo3 4.0.4
Typo3 dummy-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/dummy-4.0.5.tar.gz
Typo3 typo3_src-4.0.5.tar.gz
http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.5.tar.gz
参考网址
来源: VUPEN
名称: ADV-2007-0697
链接:http://www.frsirt.com/english/advisories/2007/0697
来源: typo3.org
链接:http://typo3.org/teams/security/security-bulletins/typo3-20070221-1
来源: OSVDB
名称: 33471
链接:http://osvdb.org/33471
来源: XF
名称: typo3-t3libformmail-header-injection(32630)
链接:http://xforce.iss.net/xforce/xfdb/32630
来源: BID
名称: 22668
链接:http://www.securityfocus.com/bid/22668
来源: SECUNIA
名称: 24207
链接:http://secunia.com/advisories/24207
受影响实体
- Typo3 Typo3:4.0.4<!--2000-1-1-->
- Typo3 Typo3:4.1:Beta<!--2000-1-1-->
- Typo3 Typo3:4.1:Rc1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...