Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 508790 (CVE-2014-2983)

Summary: <www-apps/drupal-{6.31,7.27}: information disclosure (CVE-2014-2983)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2014-04-26 14:29:20 UTC
CVE-2014-2983 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2983):

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different 
anonymous users, which allows remote anonymous users to obtain sensitive interim form input 
information in opportunistic situations via unspecified vectors.


@maintainer(s): since the fixed version is already in the tree, please remove the affected versions.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2014-05-15 01:45:42 UTC
Maintainer(s), Thank you for cleanup!

No GLSA needed as there are no stable versions.