Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 442756 (CVE-2012-4553)

Summary: <www-apps/drupal-7.16: Information disclosure and arbitrary PHP code execution (CVE-2012-4553)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4553
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2012-11-11 16:27:53 UTC
CVE-2012-4553 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4553):
  Drupal 7.x before 7.16 allows remote attackers to obtain sensitive
  information and possibly re-install Drupal and execute arbitrary PHP code
  via an external database server, related to "transient conditions."


web-apps, please drop vulnerable versions.
Comment 1 Anthony Basile gentoo-dev 2012-11-11 16:58:00 UTC
Dropped  drupal-7.15.

Still in the tree: drupal-6.26, drupal-7.16, drupal-7.17
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-11-12 12:52:37 UTC
(In reply to comment #1)
> Dropped  drupal-7.15.
> 
> Still in the tree: drupal-6.26, drupal-7.16, drupal-7.17

Thanks, Anthony.

Closing noglsa for ~arch only.