Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian 7.14-2 Moderate: Drupal 7 Remote Access Vulnerabilities Detected

debian
Calendar Grey January 20, 2014
Debian Logo
The security notice DSA-2858-2 for Drupal addresses critical vulnerabilities related to user authentication and permissions, mitigating risks effectively.
Multiple vulnerabilities have been discovered in Drupal, a fully-featured content management framework

Summary

CVE-2014-1475

Christian Mainka and Vladislav Mladenov reported a vulnerability
in the OpenID module that allows a malicious user to log in as
other users on the site, including administrators, and hijack
their accounts.

CVE-2014-1476

Matt Vance and Damien Tournoud reported an access bypass
vulnerability in the taxonomy module. Under certain circumstances,
unpublished content can appear on listing pages provided by the
taxonomy module and will be visible to users who should not have
permission to see it.

These fixes require extra updates to the database which can be done from
the administration pages. Furthermore this update introduces a new
security hardening element for the form API. Please refer to the
upstream advisory at for further
information.

For the stable distribution (wheezy), these problems have been fixed in
version 7.14-2+deb7u2.

For the testing distribution (jessie), these problems have been fixed in
version 7.26-1.

For the unstable distribution (sid),...

Read the Full Advisory

Package: drupal7
CVE ID: CVE-2014-1475 CVE-2014-1476

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here