First published: Tue May 07 2019(Updated: )
Possible Arbitrary Code Execution in Image Processing
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms-core | >=8.0.0<8.7.25>=9.0.0<9.5.6 | |
composer/typo3/cms | >=8.0.0<8.7.25>=9.0.0<9.5.6 | |
composer/typo3/cms | >=9.0.0<9.5.6 | 9.5.6 |
composer/typo3/cms | >=8.0.0<8.7.25 | 8.7.25 |
composer/typo3/cms-core | >=9.0.0<9.5.6 | 9.5.6 |
composer/typo3/cms-core | >=8.0.0<8.7.25 | 8.7.25 |
TYPO3 | >=8.0.0<8.7.25 | |
TYPO3 | >=9.0.0<9.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11832 is considered a critical vulnerability due to the risk of arbitrary code execution.
To fix CVE-2019-11832, upgrade TYPO3 to version 8.7.25 or 9.5.6 or later.
CVE-2019-11832 affects TYPO3 versions 8.0.0 to 8.7.25 and 9.0.0 to 9.5.6.
The vulnerability involves improper configuration of image processing applications like ImageMagick or GraphicsMagick.
Yes, exploiting CVE-2019-11832 can lead to remote code execution and potentially compromise your system.