Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 508790 (CVE-2014-2983) - <www-apps/drupal-{6.31,7.27}: information disclosure (CVE-2014-2983)
Summary: <www-apps/drupal-{6.31,7.27}: information disclosure (CVE-2014-2983)
Status: RESOLVED FIXED
Alias: CVE-2014-2983
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-04-26 14:29 UTC by Agostino Sarubbo
Modified: 2014-05-15 01:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-04-26 14:29:20 UTC
CVE-2014-2983 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2983):

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different 
anonymous users, which allows remote anonymous users to obtain sensitive interim form input 
information in opportunistic situations via unspecified vectors.


@maintainer(s): since the fixed version is already in the tree, please remove the affected versions.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2014-05-15 01:45:42 UTC
Maintainer(s), Thank you for cleanup!

No GLSA needed as there are no stable versions.