PT-2019-12516 · Typo3+3 · Typo3+3
Lauritz Holtmann
·
Published
2019-05-09
·
Updated
2022-05-24
·
CVE-2019-11832
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions 8.x through 8.7.24
TYPO3 versions 9.x through 9.5.5
Description
The issue allows remote code execution due to improper configuration of image processing applications, such as ImageMagick or GraphicsMagick. For a successful exploit, the GhostScript binary
gs must be available on the server system.Recommendations
For TYPO3 versions 8.x through 8.7.24, update to version 8.7.25 or later.
For TYPO3 versions 9.x through 9.5.5, update to version 9.5.6 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghostscript
Graphicsmagick
Imagemagick
Typo3