Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian DSA-1930-1 Critical: Drupal6 Remote Code Exec & XSS Issues

debian
Calendar Grey November 7, 2009
Debian Logo
Uncover the new safety bulletin regarding Drupal6 on Debian, addressing numerous remote vulnerabilities such as command injection and cross-site scripting.
Several vulnerabilities have been found in drupal6, a fully-featured content management framework

Summary

Several vulnerabilities have been found in drupal6, a fully-featured
content management framework. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2009-2372

Gerhard Killesreiter discovered a flaw in the way user signatures are
handled. It is possible for a user to inject arbitrary code via a
crafted user signature. (SA-CORE-2009-007)

CVE-2009-2373

Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site
scripting issue in the forum module, which could be exploited via the
tid parameter. (SA-CORE-2009-007)

CVE-2009-2374

Sumit Datta discovered that certain drupal6 pages leak sensible
information such as user credentials. (SA-CORE-2009-007)


Several design flaws in the OpenID module have been fixed, which could
lead to cross-site request forgeries or privilege escalations. Also, the
file upload function does not process all extensions properly leading
to the possible execution of arbitrary code.
(SA-CORE-2009-008)


For the stable distribution (lenny), the...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: drupal6
CVE IDs: CVE-2009-2372 CVE-2009-2373 CVE-2009-2374

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here