TYPO3Jack.net - Das TYPO3 Mailinglist Forum Archiv

TYPO3 Mailingliste: nicht fragen - lesen!

TYPO3 Mailingliste: nicht fragen - lesen!_RR_1-->
Zurück   TYPO3Jack.net - Das TYPO3 Mailinglist Forum Archiv > TYPO3-Mailinglists: ENGLISH > typo3-dev@lists.netfielders.de

Registrieren Hilfe Benutzerliste Kalender Suchen Heutige Beiträge Alle Foren als gelesen markieren
  #1  
Alt 21.02.2007, 04:58
Lars Houmark
Gast
 
Beiträge: n/a
Standard [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Dear users of TYPO3,

A problem has been discovered where the internal form engine can be
used for sending arbitrary mail headers, using it for purposes which
it is not meant for.

==== Component Type ====
TYPO3 Core

==== Affected Versions ====
Below 4.0.5, 4.1beta, 4.1RC1

==== Vulnerability Type ====
Email header injection

==== Severity ====
low

==== Solution ====
Update to TYPO3 version 4.0.5 or later by downloading it at:
http://typo3.org/download/packages/

==== General advice ====
Follow the recommendations that are given in the TYPO3 Security
Cookbook, which can be found on:
http://typo3.org/teams/security/

==== Credits ====
Credits go to Olivier Dobberkau, Andreas Otto, and Thorsten Kahler,
who discovered and supplied a patch for this issue.

The just released version 4.0.5, contains a lot of other non-security
related fixes, so an upgrade is highly recommended in any situation.

Regards,

Lars Houmark
TYPO3 security team


_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
Sponsored Links
  #2  
Alt 21.02.2007, 07:33
Luc de Louw
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Lars Houmark wrote:
> Dear users of TYPO3,
>
> A problem has been discovered where the internal form engine can be used
> for sending arbitrary mail headers, using it for purposes which it is
> not meant for.
>
> ==== Component Type ====
> TYPO3 Core
>
> ==== Affected Versions ====
> Below 4.0.5, 4.1beta, 4.1RC1


Does that mean that Versions 3.8.x are also affected?

Thanks,

Luc
_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #3  
Alt 21.02.2007, 09:10
Andreas Otto
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Hi Luc,

Luc de Louw wrote:
> > ==== Affected Versions ====
> > Below 4.0.5, 4.1beta, 4.1RC1

> Does that mean that Versions 3.8.x are also affected?


Yes. Every release that was made before 4.0.5 is affected.


Cheers,
Andreas

_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #4  
Alt 21.02.2007, 21:07
Tom Walter
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Lars Houmark schrieb:

> A problem has been discovered where the internal form engine can be used
> for sending arbitrary mail headers, using it for purposes which it is
> not meant for.
> ==== Severity ====
> low
>
> ==== Solution ====
> Update to TYPO3 version 4.0.5 or later by downloading it at:
> http://typo3.org/download/packages/


Thanks for those discovering and fixing this issue.

Are there any ways to fix this issue in older versions without upgrading
to 4.05 ? (like the rte-fix in December 2006 which was provided for
different versions)

Could you explain the risk a bit more specific?
What consequences could a attack have when you rate it with severity low ?

Thanks,
Tom
_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #5  
Alt 21.02.2007, 21:55
Olivier Dobberkau
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

in Beitrag mailman.1.1172092028.24995.typo3-dev...netfielders.de schrieb
Tom Walter unter t3 (AT) wnets (DOT) de am 21.02.2007 22:07 Uhr:

> Could you explain the risk a bit more specific?
> What consequences could a attack have when you rate it with severity low ?


Hi Tom,

People could tamper with the inputsfields to send spammail thru your server.

Have a look at this:

http://typo3.svn.sourceforge.net/vie...YPO3_4-0-5/t3l
ib/class.t3lib_formmail.php?r1=1646&r2=2144

I am not sure if there is going to be a patch for older versions.

Any takers for a backport?

Olivier

_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #6  
Alt 22.02.2007, 11:02
Peter Russ
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Olivier Dobberkau schrieb:
> in Beitrag mailman.1.1172092028.24995.typo3-dev...netfielders.de schrieb
> Tom Walter unter t3 (AT) wnets (DOT) de am 21.02.2007 22:07 Uhr:
>
>> Could you explain the risk a bit more specific?
>> What consequences could a attack have when you rate it with severity low ?

>
> Hi Tom,
>
> People could tamper with the inputsfields to send spammail thru your server.
>
> Have a look at this:
>
> http://typo3.svn.sourceforge.net/vie...YPO3_4-0-5/t3l
> ib/class.t3lib_formmail.php?r1=1646&r2=2144
>
> I am not sure if there is going to be a patch for older versions.
>
> Any takers for a backport?
>
> Olivier
>


We have diffs for 3.6.2/3.7.1/3.8.1 available. Where to publish as I
couldn't find any in bugs.typo3.org?

Regs. Peter.


--
Fiat lux!
Docendo discimus.
_____________________________
4Many® Services
openBC: http://www.openbc.com/go/invuid/Peter_Russ
_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #7  
Alt 22.02.2007, 11:31
Peter Russ
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Olivier Dobberkau schrieb:
[...]>
> I am not sure if there is going to be a patch for older versions.
>
> Any takers for a backport?
>
> Olivier
>

Diffs for TYPO3 3.6.2/3.7.1/3.8.1 can be found here
http://www.4many.net/81.html

Regs. Peter.

--
Fiat lux!
Docendo discimus.
_____________________________
4Many® Services
openBC: http://www.openbc.com/go/invuid/Peter_Russ
_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #8  
Alt 23.02.2007, 13:55
Olivier Dobberkau
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

in Beitrag mailman.1.1172143911.25647.typo3-dev...netfielders.de schrieb
Peter Russ unter peter.russ (AT) 4many (DOT) net am 22.02.2007 12:31 Uhr:

> Regs. Peter.


Thanks Peter.

Olivier

_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
  #9  
Alt 23.02.2007, 18:35
Tom Walter
Gast
 
Beiträge: n/a
Standard Re: [TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email headerinjection

Peter Russ schrieb:
> Diffs for TYPO3 3.6.2/3.7.1/3.8.1 can be found here


Great, thanks !
Tom
_______________________________________________
TYPO3-dev mailing list
TYPO3-dev (AT) lists (DOT) netfielders.de
http://lists.netfielders.de/cgi-bin/...info/typo3-dev
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Wong this Post!Spurl this Post!Reddit! Diesen Post bei linksilo.de bookmarken!
 

Lesezeichen

Themen-Optionen
Ansicht Thema bewerten
Thema bewerten:

Forumregeln
Es ist dir nicht erlaubt, neue Themen zu verfassen.
Es ist dir nicht erlaubt, auf Beiträge zu antworten.
Es ist dir nicht erlaubt, Anhänge hochzuladen.
Es ist dir nicht erlaubt, deine Beiträge zu bearbeiten.

BB-Code ist an.
Smileys sind an.
[IMG] Code ist an.
HTML-Code ist aus.
Trackbacks are an
Pingbacks are an
Refbacks are an


Ähnliche Themen

Thema Autor Forum Antworten Letzter Beitrag
[TYPO3-dev] Security bulletin / HTMLArea version information Wolfgang Klinger typo3-dev@lists.netfielders.de 3 21.12.2006 14:23
[TYPO3-announce] Security Bulletin TYPO3-20061010-1: fe_adminLib.inc Michael Hirdes typo3-announce@lists.netfielders.de 0 10.10.2006 14:43
[Typo3-announce] Security Bulletin TYPO3-20051107-2: th_mailformplus Ekkehard Gümbel typo3-announce@lists.netfielders.de 0 07.11.2005 15:51
[Typo3-announce] Security Bulletin TYPO3-20051107-1: chc_forum Ekkehard Gümbel typo3-announce@lists.netfielders.de 0 07.11.2005 15:50
[Typo3-announce] Security Bulletin TYPO3-20051010-1 : fe_news,fe_rtenews Ekkehard Gümbel typo3-announce@lists.netfielders.de 0 10.10.2005 14:00


Alle Zeitangaben in WEZ +1. Es ist jetzt 03:48 Uhr.


Powered by vBulletin® Version 3.7.4 (Deutsch)
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
Template-Modifikationen durch TMS

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90