Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 185039 - www-apps/drupal Forward Module Access Restriction Bypass
Summary: www-apps/drupal Forward Module Access Restriction Bypass
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/25999/
Whiteboard: ~4 [ebuild] p-y
Keywords:
Depends on:
Blocks:
 
Reported: 2007-07-12 07:21 UTC by Pierre-Yves Rofes (RETIRED)
Modified: 2007-07-12 08:08 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-12 07:21:16 UTC
A security issue has been discovered in the Drupal Forward Module, which can be exploited by malicious people to bypass certain security restrictions.

The Forward module fails to properly check for security restrictions when retrieving posts. This can be exploited to gain access to restricted information by manipulating URL arguments.

The security issue has been confirmed in Forward Module version 4.7.x-1.1 and is reported in versions prior to 5.x-1.0. Other versions may also be affected.

Solution:
Drupal 4.7.x:
Edit the source code to ensure that the access restrictions are maintained.

Drupal 5.x:
Upgrade "Forward" to version 5.x-1.0.
http://drupal.org/node/158025

Provided and/or discovered by:
Drupal Security Team
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-12 07:23:16 UTC
setting status and cc'ing maintainer.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-12 07:25:05 UTC
there is also this one: http://secunia.com/advisories/25978/
Comment 3 Roy Marples (RETIRED) gentoo-dev 2007-07-12 07:42:17 UTC
We don't ship any 3rd party modules anymore, so this issue does not affect us by default.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-12 08:08:01 UTC
oh ok, sorry for the noise.