LWN.net Logo

Fedora alert FEDORA-2008-8905 (drupal)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 8 Update: drupal-5.11-1.fc8
Date:  Thu, 16 Oct 2008 02:13:40 +0000
Message-ID:  <20081016021340.83DD0208E03@bastion.fedora.phx.redhat.com>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-8905 2008-10-16 00:49:50 -------------------------------------------------------------------------------- Name : drupal Product : Fedora 8 Version : 5.11 Release : 1.fc8 URL : http://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: Update to 5.11, security fixes: SA-2008-047 (http://drupal.org/node/318706) - File upload access bypass (file disclosure) - Access rules bypass - BlogAPI access bypass - Node validation bypass Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to http://host/drupal/update.php to run the upgrade script. -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 9 2008 Jon Ciesla <limb@jcomserv.net> - 5.11-1 - Upgrade to 5.11, SA-2008-060. - Added notes to README and drupal.conf re CVE-2008-3661. * Thu Aug 14 2008 Jon Ciesla <limb@jcomserv.net> - 5.10-1 - Upgrade to 5.10, SA-2008-047. * Thu Jul 31 2008 Jon Ciesla <limb@jcomserv.net> - 5.9-1 - Upgrade to 5.9, SA-2008-046. * Thu Jul 10 2008 Jon Ciesla <limb@jcomserv.net> - 5.8-1 - Upgrade to 5.8, SA-2008-044. * Mon Feb 4 2008 Jon Ciesla <limb@jcomserv.net> - 5.7-1 - Upgrade to 5.7, several non-security bugs fixed. * Fri Jan 11 2008 Jon Ciesla <limb@jcomserv.net> - 5.6-1 - Upgrade to 5.6, upstream security fixes. * Mon Jan 7 2008 Jon Ciesla <limb@jcomserv.net> - 5.5-2 - Include .htaccess file, BZ 427720. * Mon Dec 10 2007 Jon Ciesla <limb@jcomserv.net> - 5.5-1 - Upgrade to 5.5, critical fixes. * Thu Dec 6 2007 Jon Ciesla <limb@jcomserv.net> - 5.4-2 - Fix /files -> /var/lib/drupal dir perms, BZ 414761. * Wed Dec 5 2007 Jon Ciesla <limb@jcomserv.net> - 5.4-1 - Upgrade to 5.4, advisory ID DRUPAL-SA-2007-031. - Augmented README regarding symlinks, BZ 254228. -------------------------------------------------------------------------------- References: [ 1 ] Bug #464162 - CVE-2008-3661 drupal session hijacking https://bugzilla.redhat.com/show_bug.cgi?id=464162 [ 2 ] Bug #466741 - drupal: multiple drupal issues in < 6.5,5.11 (SA-2008-060) https://bugzilla.redhat.com/show_bug.cgi?id=466741 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds