Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Debian: DSA-2851-1 Critical: Drupal6 Account Hijack Impersonation

debian
Calendar Grey February 2, 2014
Scroller Debian
Alert regarding vulnerability in Drupal6 leading to potential account takeover. Immediate upgrade is essential to safeguard user information.
Christian Mainka and Vladislav Mladenov reported a vulnerability in the OpenID module of Drupal, a fully-featured content management framework

Summary

These fixes require extra updates to the database which can be done from
the administration pages.

For the oldstable distribution (squeeze), this problem has been fixed in
version 6.30-1.

We recommend that you upgrade your drupal6 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: drupal6
CVE ID: CVE-2014-1475

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.