LWN.net Logo

drupal6: multiple vulnerabilities

Package(s):drupal6 CVE #(s):CVE-2009-2372 CVE-2009-2373 CVE-2009-2374
Created:November 9, 2009 Updated:November 11, 2009
Description:

From the Debian advisory:

CVE-2009-2372: Gerhard Killesreiter discovered a flaw in the way user signatures are handled. It is possible for a user to inject arbitrary code via a crafted user signature. (SA-CORE-2009-007)

CVE-2009-2373: Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site scripting issue in the forum module, which could be exploited via the tid parameter. (SA-CORE-2009-007)

CVE-2009-2374: Sumit Datta discovered that certain drupal6 pages leak sensible information such as user credentials. (SA-CORE-2009-007)

Several design flaws in the OpenID module have been fixed, which could lead to cross-site request forgeries or privilege escalations. Also, the file upload function does not process all extensions properly leading to the possible execution of arbitrary code. (SA-CORE-2009-008)

Alerts:
Debian DSA-1930-1 2009-11-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds