Debian Security Advisory
DSA-2772-1 typo3-src -- cross-site scripting
- Date Reported:
- 10 Oct 2013
- Affected Packages:
- typo3-src
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2013-1464.
- More information:
-
Markus Pieton and Vytautas Paulikas discovered that the embedded video and audio player in the TYPO3 web content management system is suspectible to cross-site-scripting.
For the stable distribution (wheezy), this problem has been fixed in version 4.5.19+dfsg1-5+wheezy1.
For the testing distribution (jessie), this problem has been fixed in version 4.5.29+dfsg1-1.
For the unstable distribution (sid), this problem has been fixed in version 4.5.29+dfsg1-1.
We recommend that you upgrade your typo3-src packages.