Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 10: 2009-2869 Moderate: Drupal-cck XSS Fix Correction

fedora
Calendar Grey March 20, 2009
Dist Fedora Esm H88
Fedora 10 resolves CSRF vulnerability in drupal-cck via update FEDORA-2009-2870. Implement this for enhanced protection.
Fixes DRUPAL-SA-CONTRIB-2009-013 - XSS issue.

Summary

The Content Construction Kit allows you create and customize fields using

a web browser. The 4.7x version of CCK creates custom content types and

allows you to add custom fields to them. In Drupal 5.x custom content

types can be created in core, and CCK allows you to add custom fields to

any content type.

Fixes DRUPAL-SA-CONTRIB-2009-013 - XSS issue: https://www.drupal.org/node/406520

* Thu Mar 19 2009 Jon Ciesla - 6.x.2.2-1

- New upstream, fixes DRUPAL-SA-CONTRIB-2009-013.

* Tue Feb 24 2009 Fedora Release Engineering - 6.x.2.0-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

* Wed Nov 5 2008 Jon Ciesla - 6.x.2.0-3

- New upstream, fixes DRUPAL-SA-2008-069.

* Tue Nov 4 2008 Jon Ciesla - 6.x.2.0-2.rc10

- New upstream.

su -c 'yum update drupal-cck' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 10
Version: 6.x.2.2
Release: 1.fc10
Summary: Allows you create and customize fields using a web browser

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here