News Block

SA-CORE-2012-001 - Drupal core multiple vulnerabilities

Drupal Core Security - Wed, 02/01/2012 - 18:06
  • Advisory ID: DRUPAL-SA-CORE-2012-001
  • Project: Drupal core
  • Version: 6.x, 7.x
  • Date: 2012-February-01
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, Cross Site Request Forgery, Multiple vulnerabilities
Description Cross Site Request Forgery vulnerability in Aggregator module

CVE: CVE-2012-0826
An XSRF vulnerability can force an aggregator feed to update. Since some services are rate-limited (e.g. Twitter limits requests to 150 per hour) this could lead to a denial of service.

This issue affects Drupal 6.x and 7.x.

OpenID not verifying signed attributes in SREG and AX

CVE: CVE-2012-0825
A group of security researchers identified a flaw in how some OpenID relying parties implement Attribute Exchange (AX). Not verifying that attributes being passed through AX have been signed could allow an attacker to modify users' information.

This issue affects Drupal 6.x and 7.x.

Access bypass in File module

CVE: CVE-2012-0827
When using private files in combination with certain field access modules, the File module will allow users to download the file even if they do not have access to view the field it was attached to.

This issue affects Drupal 7.x only.

Versions affected
  • Drupal 6.x core prior to 6.23.
  • Drupal 7.x core prior to 7.11.
Solution

Install the latest version:

  • If you use Drupal 6.x upgrade to 6.23
  • If you use Drupal 7.x upgrade to 7.11

See also the Drupal core project page.

Reported by Fixed by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

SA-CORE-2012-001 - Drupal core multiple vulnerabilities

Drupal Core Security - Wed, 02/01/2012 - 18:06
  • Advisory ID: DRUPAL-SA-CORE-2012-001
  • Project: Drupal core
  • Version: 6.x, 7.x
  • Date: 2012-February-01
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, Cross Site Request Forgery, Multiple vulnerabilities
Description Cross Site Request Forgery vulnerability in Aggregator module

CVE: CVE-2012-0826
An XSRF vulnerability can force an aggregator feed to update. Since some services are rate-limited (e.g. Twitter limits requests to 150 per hour) this could lead to a denial of service.

This issue affects Drupal 6.x and 7.x.

OpenID not verifying signed attributes in SREG and AX

CVE: CVE-2012-0825
A group of security researchers identified a flaw in how some OpenID relying parties implement Attribute Exchange (AX). Not verifying that attributes being passed through AX have been signed could allow an attacker to modify users' information.

This issue affects Drupal 6.x and 7.x.

Access bypass in File module

CVE: CVE-2012-0827
When using private files in combination with certain field access modules, the File module will allow users to download the file even if they do not have access to view the field it was attached to.

This issue affects Drupal 7.x only.

Versions affected
  • Drupal 6.x core prior to 6.23.
  • Drupal 7.x core prior to 7.11.
Solution

Install the latest version:

  • If you use Drupal 6.x upgrade to 6.23
  • If you use Drupal 7.x upgrade to 7.11

See also the Drupal core project page.

Reported by Fixed by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Drupal 6.12

Drupal 6.x Upgrade Project - Thu, 05/14/2009 - 13:07

Drupal 6.12 and 5.18, maintenance releases fixing problems reported using the bug tracking system, as well as a critical security vulnerability, are now available for download. Drupal 6.12 also fixes "account page opens automatically after login" among other smaller issues.

Upgrading your existing Drupal 5 and 6 sites is strongly recommended.

For more info see Drupal 6.12 and 5.18 released, SA-CORE-2009-006 - Drupal core - Cross site scripting and Upgrade Drupal to 6.12.

read more

Drupal 6.11

Drupal 6.x Upgrade Project - Wed, 04/29/2009 - 21:03

Drupal 6.11 and 5.17, maintenance releases fixing problems reported using the bug tracking system, as well as a critical security vulnerability, are now available for download. Drupal 6.11 also fixes performance issues with the menu cache and update status cache among other smaller issues.

Upgrading your existing Drupal 5 and 6 sites is strongly recommended.

For more info see Drupal 6.11 and 5.17 released, SA-CORE-2009-005 - Drupal core - Cross site scripting and Upgrade Drupal to 6.11.

read more

BobbyMods Drupal 6.x Upgrade Project

Drupal 6.x Upgrade Project - Tue, 02/24/2009 - 14:32

Here you can find all 'loose' Drupal 6.x core upgrade projects.

If your project is maintained by BobbyMods.com then your upgrade will be found at your project.

This project is only for CORE upgrades that do not fall within a regular project.
If you need to also update modules and themes (or the need to do so arises during the update), that will be a separate project.

Pending

Drupal 6.x Upgrade Project - Tue, 02/24/2009 - 14:32
TitleIssue StatusPriorityCategoryVersionComponentChanged

read more

Syndicate content