Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2012.0038 Twvulnerabilities have been patched in Joomla! 19 March 2012 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Joomla! Operating System: Windows UNIX variants (UNIX, Linux, OSX) Impact/Access: Increased Privileges -- Existing Account Access Privileged Data -- Unknown/Unspecified Resolution: Patch/Upgrade Member content until: Wednesday, April 18 2012 OVERVIEW Two vulnerabilities have been found in Joomla! which can lead to privilege escalation and potentially privileged data leakage. [1] [2] IMPACT The vulnerabilities allow an attacker to increase their privileges and potentially obtain privileged data. Joomla! have listed the vulnerabilities as: "Programming error allows privilege escalation in some cases." [1] "Insufficient randomness leads to password reset vulnerability." [2] MITIGATION Users are advised to upgrade to version 2.5.3 or higher. [1] [2] REFERENCES [1] [20120303] - Core - Privilege Escalation http://developer.joomla.org/security/news/395-20120303-core-privilege-escalation.html [2] [20120304] - Core - Password Change http://developer.joomla.org/security/news/394-20120304-core-password-change.html AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBT2baie4yVqjM2NGpAQKNzRAAiaFsfk1lQZjmTSSUGF8aqzSsUBaInPga NtsrpDGTPZSP/a2Y6leyPB19ezj/lOKxBX+FtmBAoZdb+RbwDZapZ/ye+cQIKYug NPt3Wf0iFI42BSNn+ZVi/lPD5IJydfMnb0SsPKpzT1KOldDoL+E8rt6Qev09qs1U vVtbHQJtf5eRzD2xcmsf8x37M4Re6bQeQqWe8v98cHC9wkC/b3oNfZsPdukPX8Jc 1MRAC42+ltyJVVbeglDbrCTXm2NavnbW00jQKOqAxQXMtCWtIUVvRC3Sy1fwFzxW HMJxFGFnM579YtNy0QJMpp3WQmnguKU58BMXJ9Qetn/WTaWgyiFt4BkmM6F81uHI FqSo0GPUH4zU9GsGLi+dA8zqyV5wVYam6T26bwSDhra8U3aQ+mqTfrpkXF6ucA91 dyjr2a7UeH/AU/9gjL7rxtiVR/okFjxi7egSdIr89KNJYIPkeDq/+ML2b6rUfJJ7 /P2MV1o0N8B0SKfON67v6a7gzC30KPgBxDbTA1fMgj1FmYQh4VIVNBVjQeculkIn ZwDwa/Nb70TcNnv/B0Tn8P3TUW6e2IDhNNjhE3tgYq9qdr8SdDePFDRGUNZoS6MO Zc+tbhj4/gMTw6pO9TTAo65L48dF03exjpYfWOOHsDhfZvKHQ2QthGtKdTVMvBUA uQG7O6ratzw= =Qk3J -----END PGP SIGNATURE-----