-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10445 2009-10-14 00:46:50 -------------------------------------------------------------------------------- Name : drupal-service_links Product : Fedora 10 Version : 6.x.1.0 Release : 5.fc10 URL : https:// Summary : Enables admins to add links to a number of sites Description : The service links module enables admins to add links to a number of social bookmarking sites, blog search sites etc. Includes sites are del.icio.us, Digg, Reddit, ma.gnolia.com, Newsvine, Furl, Google, Yahoo, Technorati and IceRocket. -------------------------------------------------------------------------------- Update Information: Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3648 to the following vulnerability: Name: CVE-2009-3648 URL: https://www.cve.org /cgi-bin/cvename.cgi?name=CVE-2009-3648 Assigned: 20091009 Reference: MISC: https://www.madirish.net/ Reference: BID:36584 Reference: URL: Reference: XF:servicelinks-content-type- xss(53633) Reference: URL: Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectorswhen displaying content type names. Checked drupal-service_links in CVS and this affects Fedora 10, 11, and rawhide. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 9 2009 Jon Ciesla - 6.x.1.0-5 - Patch for CVE-2009-3648 from madirish.net, BZ 528200, 528201. * Fri Jul 24 2009 Fedora Release Engineering - 6.x.1.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Tue Feb 24 2009 Fedora Release Engineering - 6.x.1.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #528200 - CVE-2009-3648 drupal-service_links: xss vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=528200 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal-service_links' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.