Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2098-2] New typo3-src packages fix regression

    From Thijs Kinkhorst@1:229/2 to All on Tue Sep 7 20:50:01 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2098-2 [email protected] http://www.debian.org/security/ Thijs Kinkhorst September 7, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : typo3-src
    Vulnerability : several
    Problem type : local/remote
    Debian-specific: no
    CVE Id(s) : not yet available
    Debian Bug : 590719

    The update for TYPO3 in DSA 2098 introduced a regression which could
    make the backend functionality unusable. This update corrects the
    problem. For reference the original advisory below.

    Several remote vulnerabilities have been discovered in the TYPO3 web
    content management framework: cross-site Scripting, open redirection,
    SQL injection, broken authentication and session management,
    insecure randomness, information disclosure and arbitrary code
    execution. More details can be found in the Typo3 security advisory: http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-012/

    For the stable distribution (lenny), these problems have been fixed in
    version 4.2.5-1+lenny5.

    The testing distribution (squeeze) will be fixed soon.

    For the unstable distribution (sid), these problems have been fixed in
    version 4.3.5-1 (not affected by the regression).

    We recommend that you upgrade your typo3-src package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/t/typo3-src/typo3-src_4.2.5-1+lenny5.dsc
    Size/MD5 checksum: 1008 ae2679dfa995bc4d97c3385b185613f7
    http://security.debian.org/pool/updates/main/t/typo3-src/typo3-src_4.2.5-1+lenny5.diff.gz
    Size/MD5 checksum: 149043 c44d4e5f388a382673f6c921dcdc24ed
    http://security.debian.org/pool/updates/main/t/typo3-src/typo3-src_4.2.5.orig.tar.gz
    Size/MD5 checksum: 8144727 75b2e5db6ac586fb6176f329be452159

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/t/typo3-src/typo3_4.2.5-1+lenny5_all.deb
    Size/MD5 checksum: 134050 92862c44d428912c1b48dd3363fa6dd9
    http://security.debian.org/pool/updates/main/t/typo3-src/typo3-src-4.2_4.2.5-1+lenny5_all.deb
    Size/MD5 checksum: 8194252 189667ba77e8546e48f0e079da893f0f


    These files will probably be moved into the stable distribution on
    its next update.

    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: [email protected]
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJMhogoAAoJEOxfUAG2iX57VbsIAIaJ88pO35fUYk0LpOXpqu4y nzbyySK+opOHJij+6M+C7unEk/sa6EO2MrzUgs4qNjj5d7pMYh2r7goOP9oY5+To HSnWAy/AaAO4xP3mELWXzeA12HjAG2Jo5g+a++UPaFxIMF8feMfQDEZWpRksTBCC nqHT62Qs/G0IPn/1n8Ncqgu6PefpC0KeJQ95S2y2U4P2++8FvfDqpHF6EvlPFXpl VcVQYqgjQYUCHFYMfIloW/8MU3dmlDAmsYt/tNn4V5hrI1IHsGZ1XnNfXj9/GvOC Tm44MvSXg23NUAw5s9AJ2LsHsY47G7bJAiFd3MLkd30EkwYLpkLi26bISYLQPsI=
    =Ugoj
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
    • Spearb0y
      Mon Jun 8 06:51:02 2026
      from Massachusetts via SSH
    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Sun Jun 7 20:58:28 2026
      from Wales, Uk via Telnet
    • Michal Wronka
      Sun Jun 7 19:26:28 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 26:06:44
    Calls: 12,106
    Calls today: 6
    Files: 15,006
    Messages: 6,518,191

© >>> Magnum BBS <<<, 2026