Project

General

Profile

Actions

Bug #23857

closed

Missing intvals to sanitize input data in getReferenceCount and createReferenceHtml

Added by Georg Ringer about 14 years ago. Updated about 10 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2010-10-28
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.5
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
No
Sprint Focus:

Description

Function setReferences() is set to deprecated and function getReferenceCount() should be used. As the old function got an intval(), also the new one shouldn't miss it.

Function createReferenceHtml() misses an intval too.

Those are internal functions but still should be highly secure

(issue imported from #M16149)


Files

intvals.patch (753 Bytes) intvals.patch Administrator Admin, 2010-10-28 07:57
Actions #1

Updated by Helmut Hummel almost 14 years ago

This is no vulnerability, but can be discussed if we want this as security enhancement

Actions #2

Updated by Christian Kuhn almost 14 years ago

Thanks for the patch. I'll take care.

Actions #3

Updated by Helmut Hummel almost 14 years ago

There's also a discussion about that in the core-security list...

Actions #4

Updated by Ingo Renner almost 14 years ago

where / which context does this belong to? The description doesn't mention anything...

Actions #5

Updated by Susanne Moog over 13 years ago

  • Target version deleted (4.5.0)
Actions #6

Updated by Alexander Opitz over 10 years ago

  • Status changed from New to Needs Feedback
  • Is Regression set to No

Hi,

as this issue is very old. Does the problem still exists within newer versions of TYPO3 CMS (6.2.3)?

Actions #7

Updated by Alexander Opitz about 10 years ago

  • Status changed from Needs Feedback to Closed

No feedback within the last 90 days => closing this issue.

If you think that this is the wrong decision or experience this issue again, then please write to the mailing list typo3.teams.bugs with issue number and an explanation or open a new ticket and add a relation to this ticket number.

Actions

Also available in: Atom PDF