LWN.net Logo

Fedora alert FEDORA-2009-10466 (drupal-service_links)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 11 Update: drupal-service_links-6.x.1.0-5.fc11
Date:  Wed, 14 Oct 2009 01:52:34 +0000
Message-ID:  <20091014015234.050F610F850@bastion2.fedora.phx.redhat.com>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10466 2009-10-14 00:47:15 -------------------------------------------------------------------------------- Name : drupal-service_links Product : Fedora 11 Version : 6.x.1.0 Release : 5.fc11 URL : http://drupal.org/project/service_links Summary : Enables admins to add links to a number of sites Description : The service links module enables admins to add links to a number of social bookmarking sites, blog search sites etc. Includes sites are del.icio.us, Digg, Reddit, ma.gnolia.com, Newsvine, Furl, Google, Yahoo, Technorati and IceRocket. -------------------------------------------------------------------------------- Update Information: Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3648 to the following vulnerability: Name: CVE-2009-3648 URL: http://cve.mitre.org /cgi-bin/cvename.cgi?name=CVE-2009-3648 Assigned: 20091009 Reference: MISC: http://www.madirish.net/?article=251 Reference: BID:36584 Reference: URL: http://www.securityfocus.com/bid/36584 Reference: XF:servicelinks-content-type- xss(53633) Reference: URL: http://xforce.iss.net/xforce/xfdb/53633 Cross- site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names. Checked drupal-service_links in CVS and this affects Fedora 10, 11, and rawhide. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 9 2009 Jon Ciesla <limb@jcomserv.net> - 6.x.1.0-5 - Patch for CVE-2009-3648 from madirish.net, BZ 528200, 528201. * Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 6.x.1.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #528200 - CVE-2009-3648 drupal-service_links: xss vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=528200 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal-service_links' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds