Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 97649 - www-apps/drupal is affected by XML_RPC PHP flaw (CAN-2005-1921)
Summary: www-apps/drupal is affected by XML_RPC PHP flaw (CAN-2005-1921)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-07-01 13:25 UTC by Thierry Carrez (RETIRED)
Modified: 2005-07-06 01:31 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
drupal-4.6.2.ebuild (drupal-4.6.2.ebuild,2.72 KB, text/plain)
2005-07-05 08:24 UTC, Jose Luis Rivero (yoswink) (RETIRED)
no flags Details
files/postinstall-en-4.6.txt (postinstall-en-4.6.txt,2.66 KB, text/plain)
2005-07-05 08:26 UTC, Jose Luis Rivero (yoswink) (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-07-01 13:25:17 UTC
According to GulfTech advisory Drupal is also affected.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-07-01 13:34:05 UTC
Fixed version 4.6.2 is out.
Comment 2 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-07-05 08:23:10 UTC
This is a quite important security bug on drupal. I can assure you that script
kiddies can change your drupal main page with just move a finger.

We are spending too much time to solve it so i would like to contribute.
Next attachements are:

- drupal-4.6.2.ebuild
- files/postinstall-en-4.6.txt (since instructions are a bit out-of-date now)

Guys, you can make an simple diff to see what i've changed. 
Works for me in x86.

Please, test and solve it as soon as you have time.
Thanks.
Comment 3 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-07-05 08:24:21 UTC
Created attachment 62676 [details]
drupal-4.6.2.ebuild

New drupal-4.6.2.ebuild
Comment 4 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-07-05 08:26:37 UTC
Created attachment 62677 [details]
files/postinstall-en-4.6.txt

New files/postinstall-en-4.6.txt
Comment 5 Stuart Herbert (RETIRED) gentoo-dev 2005-07-05 16:28:33 UTC
st_lim@gentoo.org has beaten us both to it.  He's bumped drupal, and removed the
older versions.

Best regards,
Stu
Comment 6 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-07-05 17:32:59 UTC
Ok, we have now 4.6.2 ebuild on the tree which solved this security issue.

One more note:
If we are going to keep in the tree the two drupal branches (4.6.x and 4.5.x).
which is a good idea since upstream is maintaining both, we need to update our
4.5.x to the new version 4.5.4.
Currently, we have in portage 4.5.2 version which is affected by this (and
others) bugs.

Thanks st_lim and Stuart.

P.D: we still need to update postinstall instructions. maybe open another bug
for this woulb be better?
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-07-06 01:31:02 UTC
As far as security is concerned, since drupal is not SLOTted, the provided fixed
version is sufficient. Feel free to apply the fix to the other versions so that
our users have more choice (otherwise you should probably remove the old
affected version).

I'm closing the security bug (no GLSA, package was always ~). Feel free to
reopen it and reassign it to web-apps if you want to further work on it (or
create another one).