Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 368745 - <www-apps/drupal-{6.22,7.2}: SA-CORE-2011-001 - Multiple vulnerabilities
Summary: <www-apps/drupal-{6.22,7.2}: SA-CORE-2011-001 - Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://lists.drupal.org/pipermail/sec...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-05-25 21:48 UTC by Tom Hendrikx
Modified: 2011-07-04 00:15 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tom Hendrikx 2011-05-25 21:48:47 UTC
As published per e-mail on secutiy-news@drupal.org mailing list [1], both Drupal version 6 and 7 have multiple vulnerabilities.

Drupal 5, which is still available in portage, is not commented on, but on the website is stated "Drupal 5 will no longer be maintained when Drupal 7 is released." [2]

[1] http://lists.drupal.org/pipermail/security-news/2011-May/000256.html
[2] http://drupal.org/node/3060/release?api_version[]=78

Please handle accordingly :)
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2011-05-26 18:39:17 UTC
Thanks for the report, Tom.

From $URL:

  * Advisory ID: DRUPAL-SA-CORE-2011-001
  * Project: Drupal core [1]
  * Version: 6.x, 7.x
  * Date: 2011-May-25
  * Security risk: Critical [2]
  * Exploitable from: Remote
  * Vulnerability: Access bypass, Cross Site Scripting

-------- DESCRIPTION  
---------------------------------------------------------

Multiple vulnerabilities and weaknesses were discovered in Drupal.

.... Reflected cross site scripting vulnerability in error handler

A reflected cross site scripting vulnerability was discovered in Drupal's
error handler. Drupal displays PHP errors in the messages area, and a
specially crafted URL can cause malicious scripts to be injected into the
message. The issue can be mitigated by disabling on-screen error display at
admin/settings/error-reporting. This is the recommended setting for
production sites.

This issue affects Drupal 6.x only.

.... Cross site scripting vulnerability in Color module

When using re-colorable themes, color inputs are not sanitized. Malicious
color values can be used to insert arbitrary CSS and script code. Successful
exploitation requires the "Administer themes" permission.

This issue affects Drupal 6.x and 7.x.

.... Access bypass in File module

When using private files in combination with a node access module, the File
module allows unrestricted access to private files.

This issue affects Drupal 7.x only.

-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Drupal 7.x before version 7.1.
  * Drupal 6.x before version 6.21.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-07-04 00:15:16 UTC
Fixed packages are in the tree. Closing noglsa.