[TYPO3-UG Russia] Fwd: [TYPO3-announce] TYPO3-SA-2009-002: Information Disclosure & XSS in TYPO3 Core

Michael Shigorin mike at osdn.org.ua
Tue Feb 10 10:21:31 CET 2009


----- Forwarded message from Lars Houmark <lars/typo3.org> -----

Date: Tue, 10 Feb 2009 04:05:12 -0500
From: Lars Houmark <lars/typo3.org>
To: TYPO3 Announce List <typo3-announce/lists.netfielders.de>
Subject: [TYPO3-announce] TYPO3-SA-2009-002: Information Disclosure & XSS in TYPO3 Core

Dear users of TYPO3,

It has been discovered that TYPO3 Core is vulnerable to Information  
Disclosure and Cross-Site Scripting.

Especially the first issue is considered to be very critical by the  
TYPO3 Security Team.

New packaged versions (4.0.x, 4.1.x, 4.2.x) along with patches for all  
versions since 3.3 is now available.

Please read the below bulletin for the complete details and solutions:

http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/

Regards,

Lars Houmark
TYPO3 Security Team
_______________________________________________
TYPO3-announce mailing list
TYPO3-announce/lists.netfielders.de
http://lists.netfielders.de/cgi-bin/mailman/listinfo/typo3-announce

----- End forwarded message -----

-- 
 ---- WBR, Michael Shigorin <mike at altlinux.ru>
  ------ Linux.Kiev http://www.linux.kiev.ua/


More information about the TYPO3-russia mailing list