CVE-2014-8325
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
22/10/2014
Last modified:
12/04/2025
Description
The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denial of service (resource consumption) via vectors related to the PHP PCRE library.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:calender_base_project:calender_base:*:*:*:*:*:typo3:*:* | 1.5.8 (including) | |
cpe:2.3:a:calender_base_project:calender_base:1.5.0:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.1:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.2:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.3:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.4:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.5:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.6:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.5.7:*:*:*:*:typo3:*:* | ||
cpe:2.3:a:calender_base_project:calender_base:1.6.0:*:*:*:*:typo3:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://typo3.org/extensions/repository/view/cal
- http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-013/
- http://www.openwall.com/lists/oss-security/2014/10/17/11
- http://www.securityfocus.com/bid/70645
- http://typo3.org/extensions/repository/view/cal
- http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-013/
- http://www.openwall.com/lists/oss-security/2014/10/17/11
- http://www.securityfocus.com/bid/70645