Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 447940 (CVE-2012-5651) - <www-apps/drupal-{6.27,7.18}: Multiple vulnerabilities (CVE-2012-{5651,5652,5653})
Summary: <www-apps/drupal-{6.27,7.18}: Multiple vulnerabilities (CVE-2012-{5651,5652,5...
Status: RESOLVED FIXED
Alias: CVE-2012-5651
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial with 1 vote (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-20 11:17 UTC by Tupone Alfredo
Modified: 2013-01-15 21:44 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tupone Alfredo gentoo-dev 2012-12-20 11:17:35 UTC
drupal-6.27 fixes vulnerability

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

    SA-CORE-2012-004 - Drupal core - Multiple vulnerabilities

No other fixes are included.

Reproducible: Always
Comment 1 Lari Korpi 2012-12-20 16:04:34 UTC
This issue is also on Drupal 7 so both need version bumps.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-01-03 11:35:51 UTC
CVE-2012-5653 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5653):
  The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows
  remote authenticated users to bypass the protection mechanism and execute
  arbitrary PHP code via a null byte in a file name.

CVE-2012-5652 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5652):
  Drupal 6.x before 6.27 allows remote attackers to obtain sensitive
  information about uploaded files via a (1) RSS feed or (2) search result.

CVE-2012-5651 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5651):
  Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked
  users, which might allow remote attackers to obtain sensitive information by
  reading the search results.
Comment 3 Lari Korpi 2013-01-04 11:40:26 UTC
I copied the drupal-7.17.ebuild into local overlay as drupal-7.18.ebuild and emerged the drupal-7.18.

No issues with 7.18 so far.
Comment 4 Tim Harder gentoo-dev 2013-01-13 07:24:55 UTC
6.27 and 7.18 added to CVS, old versions removed.
Comment 5 MickKi 2013-01-13 10:10:15 UTC
When will this make it into portage?  I just had a drupal-7.17 hacked!
-- 
Regards,
Comment 6 Sean Amoss (RETIRED) gentoo-dev Security 2013-01-15 21:44:08 UTC
(In reply to comment #4)
> 6.27 and 7.18 added to CVS, old versions removed.

Thanks, Tim!

Closing noglsa for ~arch only.