Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 114174 - www-apps/drupal multiple issues
Summary: www-apps/drupal multiple issues
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-01 11:33 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2006-01-03 02:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-01 11:33:14 UTC
Bypass "view user profiles" permission 
http://drupal.org/node/39356 
 
XSS vulnerability in submitted content 
http://drupal.org/node/39353 
 
XSS and HTTP header injection vulnerability with uploaded files 
http://drupal.org/node/39355
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-12-03 08:23:17 UTC
Please bump to 4.6.4
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-02 13:15:03 UTC
web-apps any news on this one?
Comment 3 Alexandre Ghisoli 2006-01-03 01:35:07 UTC
drupal 4.6.5 is out as ebuild, but seems to be broken.

maintener could close this one
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2006-01-03 02:26:08 UTC
Yes, borken but fixed in security PoV so closing this one. 
If no bug was created for fixing the 4.6.5 brokeness, please do :)