===================================================================== CERT-Renater Note d'Information No. 2009/VULN302 _____________________________________________________________________ DATE : 31/07/2009 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Systems running third party extensions for TYPO3. ====================================================================== http://lists.netfielders.de/pipermail/typo3-announce/2009/000120.html http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-010/ ______________________________________________________________________ Dear users of TYPO3, Security vulnerabilities have been discovered in following third party TYPO3 extensions: "CoolURI" (cooluri) "Reset backend password" (cwt_resetbepassword) "datamints Newsticker" (datamints_newsticker) "[Gobernalia] Front End News Submitter" (gb_fenewssubmit) "Mailform" (mailform) "Myth download" (myth_download) "Tour Extension" (pm_tour) "Twitter Search" (twittersearch) "Webesse E-Card" (ws_ecard) "Webesse Image Gallery" (ws_gallery) For further information on all CSB (Collective Security Bulletin) issues , please read the related advisory TYPO3-SA-2009-010 that was published today: In general, the TYPO3 Security Team recommends to read the following pages: The TYPO3 Security Cookbook: Make sure you are subscribed to the TYPO3 Announce List: See all TYPO3 security advisories: Regards, Marcus Krause Member of the TYPO3 Security Team -- TYPO3 Security Team homepage: http://typo3.org/teams/security/ E-Mail: security at typo3.org ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================