CVE-2014-9508

NameCVE-2014-9508
DescriptionThe frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs775105

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
typo3-srcsource(unstable)4.5.40+dfsg1-1medium775105
typo3-srcsourcesqueeze(unfixed)end-of-life
typo3-srcsourcewheezy(unfixed)end-of-life

Notes

[wheezy] - typo3-src <end-of-life> (See DSA 3314)
[squeeze] - typo3-src <end-of-life> (Unsupported in squeeze-lts)
https://review.typo3.org/#/c/35222/
https://review.typo3.org/gitweb?p=Packages/TYPO3.CMS.git;a=commitdiff;h=63ae7ddd11d284a121f23ce86282e3149bc16f96

Search for package or bug name: Reporting problems