TYPO3 HTTP Host Header Spoofing Vulnerability
BID:67626
Info
TYPO3 HTTP Host Header Spoofing Vulnerability
| Bugtraq ID: | 67626 |
| Class: | Design Error |
| CVE: |
CVE-2014-3941 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2014 12:00AM |
| Updated: | Jun 23 2014 12:03AM |
| Credit: | Helmut Hummel |
| Vulnerable: |
Typo3 Typo3 4.5.13 Typo3 Typo3 4.5.8 Typo3 Typo3 4.5.7 Typo3 Typo3 4.5.5 Typo3 Typo3 4.5.9 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.4 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5.2 Typo3 Typo3 4.5.15 Typo3 Typo3 4.5.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
TYPO3 HTTP Host Header Spoofing Vulnerability
TYPO3 is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
Attackers can exploit this issue to spoof and impersonate a legitimate host, Other attacks are also possible.
TYPO3 4.5.0 to 4.5.33, 4.7.0 to 4.7.18, 6.0.0 to 6.0.13, 6.1.0 to 6.1.8 and 6.2.0 to 6.2.2 are vulnerable.
TYPO3 is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
Attackers can exploit this issue to spoof and impersonate a legitimate host, Other attacks are also possible.
TYPO3 4.5.0 to 4.5.33, 4.7.0 to 4.7.18, 6.0.0 to 6.0.13, 6.1.0 to 6.1.8 and 6.2.0 to 6.2.2 are vulnerable.
Exploit / POC
TYPO3 HTTP Host Header Spoofing Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
TYPO3 HTTP Host Header Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.