Charlottezweb

General Conversation => Script Chat => Topic started by: Jason on March 28, 2012, 09:13:19 AM

Title: Joomla Security Notice :: March 28, 2012
Post by: Jason on March 28, 2012, 09:13:19 AM
Email below sent from Joomla this morning:

http://developer.joomla.org/security/news/

Quote
Joomla! Security News
   

[20120305] - Core - Password Change

Posted: 28 Mar 2012 12:21 AM PDT

    * Project: Joomla!
    * SubProject: All
    * Severity: High
    * Versions: 1.5.25 and all earlier 1.5.x versions
    * Exploit type: Password Change
    * Reported Date: 2012-March-8
    * Fixed Date: 2012-March-27

Description

Insufficient randomness leads to password reset vulnerability.
Affected Installs

Joomla! versions 1.5.25 and all earlier 1.5.x versions
Solution

Upgrade to version 1.5.26

Reported by George Argyros and Aggelos Kiayias
Contact

The JSST at the Joomla! Security Center.

[20120306] - Core - Information Disclosure

Posted: 28 Mar 2012 12:21 AM PDT

    * Project: Joomla!
    * SubProject: All
    * Severity: Low
    * Versions: 1.5.25 and all earlier 1.5.x versions
    * Exploit type: Information Disclosure
    * Reported Date: 2012-January-7
    * Fixed Date: 2012-March-27

Description

Inadequate permission checking allows unauthorised viewing of administrative back end information.
Affected Installs

Joomla! versions 1.5.25 and all earlier 1.5.x versions
Solution

Upgrade to version 1.5.26