ASA-2019-00415 – TYPO3: Possible deserialization side-effects in symfony/cache


Allele Security Alert

ASA-2019-00415

Identifier(s)

ASA-2019-00415, CVE-2019-10912, TYPO3-CORE-SA-2019-016

Title

Possible deserialization side-effects in symfony/cache

Vendor(s)

TYPO3 Association

Product(s)

TYPO3 CMS

Affected version(s)

TYPO3 CMS versions 9.4.0 to 9.5.7

Fixed version(s)

TYPO3 CMS version 9.5.8

Proof of concept

Unknown

Description

Third party component symfony/cache could have been potentially leading to removal of arbitrary files in combination with other insecure deserialization vulnerabilities.

Technical details

Unknown

Credits

Oliver Hader

Reference(s)

TYPO3 9.5.8 and 8.7.27 security releases published
https://typo3.org/article/typo3-958-and-8727-security-releases-published/

TYPO3-CORE-SA-2019-016: Possible deserialization side-effects in symfony/cache
https://typo3.org/security/advisory/typo3-core-sa-2019-016/

[TYPO3-announce] Announcing TYPO3 v9.5.8 and v8.7.27 security releases
http://lists.typo3.org/pipermail/typo3-announce/2019/000447.html

CVE-2019-10912: Prevent destructors with side-effects from being unserialized
https://symfony.com/blog/cve-2019-10912-prevent-destructors-with-side-effects-from-being-unserialized

CVE-2019-10912
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10912

CVE-2019-10912
https://nvd.nist.gov/vuln/detail/CVE-2019-10912

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 11, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.