-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3164-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff February 21, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : typo3-src CVE ID : not yet available Pierrick Caillon discovered that the authentication could be bypassed in the Typo 3 content management system. Please refer to the upstream advisory for additional information: https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-001/ For the stable distribution (wheezy), this problem has been fixed in version 4.5.19+dfsg1-5+wheezy4. The upcoming stable distribution (jessie) no longer includes Typo 3. For the unstable distribution (sid), this problem has been fixed in version 4.5.40+dfsg1-1. We recommend that you upgrade your typo3-src packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org