CVE-2006-2742
A SQL injection vulnerability has been discovered in the "count" and
"from" variables of the database interface.
CVE-2006-2743
Multiple file extensions were handled incorrectly if Drupal ran on
Apache with mod_mime enabled.
CVE-2006-2831
A variation of CVE-2006-2743 was adressed as well.
CVE-2006-2832
A Cross-Site-Scripting vulnerability in the upload module has been
discovered.
CVE-2006-2833
A Cross-Site-Scripting vulnerability in the taxonomy module has been
discovered.
For the stable distribution (sarge) these problems have been fixed in
version 4.5.3-6.1sarge2.
For the unstable distribution (sid) these problems have been fixed in
version 4.5.8-1.1.
We recommend that you upgrade your drupal packages.
Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources....
Get the latest Linux and open source security news straight to your inbox.