Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 442756 (CVE-2012-4553) - <www-apps/drupal-7.16: Information disclosure and arbitrary PHP code execution (CVE-2012-4553)
Summary: <www-apps/drupal-7.16: Information disclosure and arbitrary PHP code executio...
Status: RESOLVED FIXED
Alias: CVE-2012-4553
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-11 16:27 UTC by GLSAMaker/CVETool Bot
Modified: 2012-11-12 12:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-11-11 16:27:53 UTC
CVE-2012-4553 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4553):
  Drupal 7.x before 7.16 allows remote attackers to obtain sensitive
  information and possibly re-install Drupal and execute arbitrary PHP code
  via an external database server, related to "transient conditions."


web-apps, please drop vulnerable versions.
Comment 1 Anthony Basile gentoo-dev 2012-11-11 16:58:00 UTC
Dropped  drupal-7.15.

Still in the tree: drupal-6.26, drupal-7.16, drupal-7.17
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-11-12 12:52:37 UTC
(In reply to comment #1)
> Dropped  drupal-7.15.
> 
> Still in the tree: drupal-6.26, drupal-7.16, drupal-7.17

Thanks, Anthony.

Closing noglsa for ~arch only.