CVE-2009-0258: Input Validation
The Indexed Search Engine (indexedsearch) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.2.4 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.1.8 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0258?
CVE-2009-0258 has a high severity rating due to its potential to allow remote command execution.
How do I fix CVE-2009-0258?
To fix CVE-2009-0258, upgrade TYPO3 to version 4.2.4, 4.1.8, or 4.0.10, depending on your current version.
What versions of TYPO3 are affected by CVE-2009-0258?
CVE-2009-0258 affects TYPO3 versions 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3.
Can CVE-2009-0258 be exploited without authentication?
Yes, CVE-2009-0258 can be exploited by remote attackers without requiring authentication.
What types of attacks does CVE-2009-0258 allow?
CVE-2009-0258 allows unauthorized remote execution of arbitrary commands via crafted filenames.