Joomla critical patch ...upgrade to 3.4.6

Security annoucements of interest to the AtomiCorp community, such as vulnerabilities in third party applications.
BruceLee
Forum Regular
Forum Regular
Posts: 879
Joined: Sat Mar 28, 2009 6:58 pm
Location: Germany

Joomla critical patch ...upgrade to 3.4.6

Unread post by BruceLee »

Hi everybody,

for your info. and a question to atomicorp if ASL covers this.
Thanks a lot.
[20151201] - Core - Remote Code Execution Vulnerability

Project: Joomla!
SubProject: CMS
Severity: High
Versions: 1.5.0 through 3.4.5
Exploit type: Remote Code Execution
Reported Date: 2015-December-13
Fixed Date: 2015-December-14
CVE Numbers: requested

Description:
Browser information is not filtered properly while saving the session values into the database which leads to a Remote Code Execution vulnerability.

Affected Installs:
Joomla! CMS versions 1.5.0 through 3.4.5

Solution:
Upgrade to version 3.4.6
SOURCE:
https://developer.joomla.org/security-c ... ility.html

Patch in branch 3.X:
https://github.com/joomla/joomla-cms/releases/tag/3.4.6
Patches for EOL versions:
https://docs.joomla.org/Security_hotfix ... L_versions
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Joomla critical patch ...upgrade to 3.4.6

Unread post by mikeshinn »

Yes ASL, and the modsecurity rules, already protect against this attack. Both generically (there are rules for malicious payloads in the UA and other fields), as well as specific JITP rules for this vulnerability in Joomla.
BruceLee
Forum Regular
Forum Regular
Posts: 879
Joined: Sat Mar 28, 2009 6:58 pm
Location: Germany

Re: Joomla critical patch ...upgrade to 3.4.6

Unread post by BruceLee »

JEEHAAAA. :) Thanks like always.
awsumco
New Forum User
New Forum User
Posts: 1
Joined: Thu Dec 17, 2015 3:04 am
Location: The Moon

Re: Joomla critical patch ...upgrade to 3.4.6

Unread post by awsumco »

Hi, mikeshinn

Out of curiosity which mod_sec rule config covers the said Joomla vulnerability, i just want to double check I am in fact covered as I only used the ASL mod_sec rules subscription ?
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Joomla critical patch ...upgrade to 3.4.6

Unread post by mikeshinn »

337106 and 347195
Post Reply