Several remote vulnerabilities have been discovered in the TYPO3 web
content management framework: cross-site Scripting, open redirection,
SQL injection, broken authentication and session management,
insecure randomness, information disclosure and arbitrary code
execution. More details can be found in the Typo3 security advisory:
https://typo3.org/security/advisory/typo3-sa-2010-012
For the stable distribution (lenny), these problems have been fixed in
version 4.2.5-1+lenny5.
The testing distribution (squeeze) will be fixed soon.
For the unstable distribution (sid), these problems have been fixed in
version 4.3.5-1 (not affected by the regression).
We recommend that you upgrade your typo3-src package.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upg...
Get the latest Linux and open source security news straight to your inbox.