CVE-2010-4962: Code Injection
Published Oct 9, 2011
·Updated
Unspecified vulnerability in the Webkit PDFs (webkitpdf) extension before 1.1.4 for TYPO3 allows remote attackers to execute arbitrary commands via unknown vectors.
Affected Software
13 affected componentsFixes available
Dev-team Typoheads Webkitpdf<=1.1.3
Dev-team Typoheads Webkitpdf=1.0.2
Dev-team Typoheads Webkitpdf=1.1.0
Dev-team Typoheads Webkitpdf=1.1.1
Dev-team Typoheads Webkitpdf=1.1.2
Typo3 TYPO3
composer/dmk/webkitpdf<1.1.4
1.1.4
All of the following
Any of the following
Dev-team Typoheads Webkitpdf<=1.1.3
Dev-team Typoheads Webkitpdf=1.0.2
Dev-team Typoheads Webkitpdf=1.1.0
Dev-team Typoheads Webkitpdf=1.1.1
Dev-team Typoheads Webkitpdf=1.1.2
Typo3 TYPO3
Remediation
Patch Available
Event History
Oct 9, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:55 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·10:55 AM
RemedyDescriptionSeverityAffected Software
May 17, 2022
Advisory Published
via GitHub·01:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-4962?
CVE-2010-4962 is considered to allow remote attackers to execute arbitrary commands, indicating a high level of severity.
2
How do I fix CVE-2010-4962?
To fix CVE-2010-4962, upgrade the Webkit PDFs extension to version 1.1.4 or later.
3
What software is affected by CVE-2010-4962?
CVE-2010-4962 affects versions of the Webkit PDFs extension for TYPO3 prior to 1.1.4.
4
Can CVE-2010-4962 be exploited remotely?
Yes, CVE-2010-4962 can be exploited remotely by attackers to execute arbitrary commands.
5
Is there a known fix or patch for CVE-2010-4962?
The known fix for CVE-2010-4962 is to update to the fixed version of Webkit PDFs extension 1.1.4.