First published: Wed Nov 23 2011(Updated: )
The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.5.24 | |
Joomla | =1.5.11 | |
Joomla | =1.5.13 | |
Joomla | =1.5.3 | |
Joomla | =1.5.2 | |
Joomla | =1.5.22 | |
Joomla | =1.5.9 | |
Joomla | =1.5.18 | |
Joomla | =1.5.16 | |
Joomla | =1.5.4 | |
Joomla | =1.5.10 | |
Joomla | =1.5.7 | |
Joomla | =1.5.0 | |
Joomla | =1.5.15 | |
Joomla | =1.5.6 | |
Joomla | =1.5.1 | |
Joomla | =1.5.23 | |
Joomla | =1.5.17 | |
Joomla | =1.5.8 | |
Joomla | =1.5.19 | |
Joomla | =1.5.21 | |
Joomla | =1.5.12 | |
Joomla | =1.5.5 | |
Joomla | =1.5.20 | |
Joomla | =1.5.15-rc | |
Joomla | =1.5.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4321 is considered to have a medium severity level due to its potential to allow attackers to change passwords.
To fix CVE-2011-4321, upgrade Joomla! to the latest version beyond 1.5.24, as this vulnerability has been addressed in subsequent releases.
CVE-2011-4321 affects Joomla! versions 1.5.0 through 1.5.24.
CVE-2011-4321 enables attackers to change the passwords of arbitrary users using weak random number generation.
There are no effective workarounds for CVE-2011-4321; upgrading to a patched version is the recommended action.