CVE-2009-0255: High severity Typo3 TYPO3 vulnerability
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Identify TYPO3 installations running versions 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, or 4.2.0 through 4.2.3. For each affected instance, regenerate the encryption key created by the System extension "Install tool" (the key is generated with an insufficiently random seed in these versions). Replace the weak key with a newly generated key produced by a cryptographically secure random source and rotate or re-encrypt any data or credentials protected by the old key.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0255?
CVE-2009-0255 has a severity rating that indicates it poses a significant risk due to its potential exploitation.
How do I fix CVE-2009-0255?
To fix CVE-2009-0255, you should upgrade TYPO3 to version 4.2.4 or later, which addresses this vulnerability.
What versions of TYPO3 are affected by CVE-2009-0255?
CVE-2009-0255 affects TYPO3 versions 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3.
What is the impact of CVE-2009-0255?
The impact of CVE-2009-0255 could allow attackers to potentially crack the encryption key due to an insufficiently random seed.
Are there any workarounds for CVE-2009-0255?
There are no specific workarounds for CVE-2009-0255, and upgrading the software is the recommended action.