Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 543734 (CVE-2015-2559) - <www-apps/drupal-{6.35,7.35}: Multiple vulnerabilities (CVE-2015-2559)
Summary: <www-apps/drupal-{6.35,7.35}: Multiple vulnerabilities (CVE-2015-2559)
Status: RESOLVED FIXED
Alias: CVE-2015-2559
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://www.drupal.org/SA-CORE-2015-001
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-18 21:54 UTC by MickKi
Modified: 2015-03-28 17:27 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description MickKi 2015-03-18 21:54:43 UTC
Please see SA-CORE-2015-001 describing drupal <6.35 and <7.35 vulnerabilities for Access Bypass (Password reset URLs) and Open Redirect (Several vectors including the "destination" URL parameter).



Reproducible: Always
Comment 1 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-03-20 18:07:54 UTC
Versions affected
    Drupal core 6.x versions prior to 6.35
    Drupal core 7.x versions prior to 7.35

Solution
Install the latest version:
    If you use the Drupal 6.x, upgrade to Drupal core 6.35
    If you use the Drupal 7.x, upgrade to Drupal core 7.35


This package is not stable, so please cleanup and close after bump.
Comment 2 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-03-20 18:20:47 UTC
7.35 was done yesterday. I'll bump 6.35 later today.
Comment 3 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-03-21 23:32:06 UTC
23:28 < gentoovcs> jmbsvicetto → gentoo-x86 (www-apps/drupal/) Bump to 7.35 version that addresses SA-CORE-2015-001 - bug 543734.
23:30 < gentoovcs> jmbsvicetto → gentoo-x86 (www-apps/drupal/) Fix commit message - s/7.35/6.35/.

Bump and clean-up done, so I'm closing the bug as fixed.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2015-03-28 17:27:33 UTC
CVE-2015-2559 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2559):
  Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users
  to reset the password of other accounts by leveraging an account with the
  same password hash as another account and a crafted password reset URL.