Skip directly to content

Feed aggregator

SA-CONTRIB-2012-149 - Hostip - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 10/03/2012 - 15:10
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-149
  • Project: Hostip (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-October-03
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

Hostip enables you to query the http://www.hostip.info/ API to get the country / state information based on the user's IP address or a specific IP passed to it. The module fails to sanitize data retrieved from an untrusted third party source, thereby exposing an arbitrary script injection vulnerability (XSS).

This vulnerability is mitigated by the fact that an attacker must have either gained access to that third party source or use techniques such as DNS spoofing in order to inject malicious data.

CVE: Requested

Versions affected
  • Hostip 6.x-2.x versions prior to 6.x-2.2.
  • Hostip 7.x-2.x versions prior to 7.x-2.2.

Drupal core is not affected. If you do not use the contributed Hostip module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Hostip module for Drupal 6.x, upgrade to Hostip 6.x-1.2
  • If you use the Hostip module for Drupal 7.x, upgrade to Hostip 7.x-1.2

Also see the Hostip project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-148 - OG - Access Bypass

Drupal Contrib Security Announcements - Wed, 09/26/2012 - 20:46
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-148
  • Project: Organic groups (third-party module)
  • Version: 7.x
  • Date: 2012-September-26
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Description

OG (Organic groups) enables users to create and manage their own 'groups'. Each group can have subscribers, and maintains a group home page where subscribers communicate amongst themselves. A group membership can be given immediately upon subscribing, or be pending - waiting for a group administrator to approve it.

OG doesn't properly maintain pending memberships if the user is allowed to edit their own account.

In addition, under certain circumstances, a user was able to post to a group which they were not a member of.

There are no additional mitigating factors for these issues.

CVE: Requested

Versions affected
  • OG (Organic groups) 7.x-1.x versions prior to 7.x-1.5.

Drupal core is not affected. If you do not use the contributed Organic groups module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Organic groups project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-147 - FileField Sources - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/19/2012 - 17:12
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-147
  • Project: FileField Sources (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-September-19
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

The Drupal FileField module lets you upload files from your computer through a CCK field. The FileField Sources module expands on this ability by allowing you to select new or existing files through additional means. The FileField Sources module contains a persistent cross site scripting (XSS) vulnerability due to the fact that it fails to sanitize user supplied filenames before display.

This vulnerability is mitigated by the fact that malicious users must have the ability to upload files on a field that has the "Reference existing" source enabled.

CVE: Requested

Versions affected
  • FileField Sources 6.x-1.x versions prior to 6.x-1.6.
  • FileField Sources 7.x-1.x versions prior to 7.x-1.6.

Drupal core is not affected. If you do not use the contributed FileField Sources module, there is nothing you need to do.

Solution

Install the latest version:

Also see the FileField Sources project page.

Reported by
  • Disclosed publicly.
Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-146 - Simplenews Scheduler - Arbitrary code execution

Drupal Contrib Security Announcements - Wed, 09/19/2012 - 16:52
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-146
  • Project: Simplenews Scheduler (third-party module)
  • Version: 6.x
  • Date: 2012-September-19
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Arbitrary PHP code execution
Description

The Simplenews Scheduler module provides a system for creating automatic email newsletters. These can be set to be sent at a fixed interval, or PHP code can be entered to evaluate a condition for a new newsletter issue to be sent.

The module allows a user with the 'send scheduled newsletters' access to the scheduling form where PHP code may be entered. This code is then executed the next time the site runs cron. A site administrator granting permissions is not given sufficient warning that they are granting this level of access to the site.

This vulnerability is mitigated by the fact that an attacker must have already been granted a role with the permission 'send scheduled newsletters'.

CVE: Requested

Versions affected
  • Simplenews Scheduler 6.x-2.x versions prior to 6.x-2.3.

Drupal core is not affected. If you do not use the contributed Simplenews Scheduler module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Simplenews Scheduler project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-145 - Imagemenu - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/19/2012 - 16:37
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-145
  • Project: Imagemenu (third-party module)
  • Version: 6.x
  • Date: 2012-September-19
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

Imagemenu module allows you to create Drupal menus from images files.

The module doesn't sufficiently escape image file names when rendering menus, allowing a potential XSS attack.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer imagemenu".

CVE: Requested

Versions affected
  • Imagemenu 6.x-1.x versions prior to 6.x-1.4.

Drupal core is not affected. If you do not use the contributed Imagemenu module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Imagemenu project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-144 Fonecta verify - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/19/2012 - 16:37
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-144
  • Project: Fonecta verify (third-party module)
  • Version: 7.x
  • Date: 2012-September-19
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

Fonecta verify provides an interface to retrieve information from the Finnish Fonecta company information database. The module contains an arbitrary script injection vulnerability (XSS) due to the fact that it fails to sanitize data retrieved from an untrusted third party source.

This vulnerability is mitigated by the fact that an attacker must have either gained access to that third party source or use techniques such as DNS spoofing in order to inject malicious data.

CVE: Requested

Versions affected
  • Fonecta verify 7.x-1.x versions prior to 7.x-1.6.

Drupal core is not affected. If you do not use the contributed Fonecta verify module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Fonecta verify project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-143 PRH Search - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/19/2012 - 16:34
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-143
  • Project: PRH Search (third-party module)
  • Version: 7.x
  • Date: 2012-September-19
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

PRH Search provides an interface to search for association information for Finnish association using the PRH (Patentti- ja Rekisterihallitus) database. The module fails to sanitize data retrieved from an untrusted third party source, thereby exposing an arbitrary script injection vulnerability (XSS).

This vulnerability is mitigated by the fact that an attacker must have either gained access to that third party source or use techniques such as DNS spoofing in order to inject malicious data.

CVE: Requested

Versions affected
  • PRH Search 7.x-1.x versions prior to 7.x-1.1

Drupal core is not affected. If you do not use the contributed PRH Search module, there is nothing you need to do.

Solution

Install the latest version:

Also see the PRH Search project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-142 - Spambot - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/19/2012 - 16:17
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-142
  • Project: Spambot (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-September-19
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

The Spambot module enables you to protect new user registrations from spammers using the database at stopforumspam.com.

Spambot doesn't sufficiently sanitize API responses from stopforumspam.com when they are logged to the watchdog, allowing a potential XSS attack.

This vulnerability is mitigated by the fact that only stopforumspam.com (or someone pretending to be stopforumspam.com) can exploit it.

CVE: Requested

Versions affected
  • Spambot 6.x-3.x versions prior to 6.x-3.2.
  • Spambot 7.x-1.x versions prior to 7.x-1.1.

Drupal core is not affected. If you do not use the contributed Spambot module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Spambot project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-141 - Mass Contact - Access bypass

Drupal Contrib Security Announcements - Wed, 09/12/2012 - 20:38
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-141
  • Project: Mass Contact (third-party module)
  • Version: 6.x
  • Date: 2012-September-12
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Description

This module allows anyone with permission to send a single message to multiple users of a site, using its roles functionality.

The module doesn't sufficiently check permissions after the form has been submitted.

This vulnerability is mitigated by the fact that an attacker must use a tool of some kind (like the Tamper Data Firefox add-on) to intercept the form submission request in order to modify the settings.

CVE: Requested

Versions affected
  • Mass Contact 6.x-1.x versions prior to 6.x-1.2.

Drupal core is not affected. If you do not use the contributed Mass Contact module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Mass Contact project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-140 - Inf08 - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/12/2012 - 18:18
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-140
  • Project: Inf08 (third-party module)
  • Version: 6.x
  • Date: 2012-September-12
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

Inf08 is a valid XHTML 1.0 Strict / CSS 2.1 theme ported from the free CSS template. The theme contains an arbitrary script injection vulnerability (XSS) due to the fact that it fails to sanitize user supplied taxonomy vocabulary names before display. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer taxonomy".

CVE: Requested

Versions affected
  • Inf08 6.x-1.x versions prior to 6.x-1.10.

Drupal core is not affected. If you do not use the contributed Inf08 module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Inf08 theme for Drupal 6.x, upgrade to Inf08 6.x-1.10

Also see the Inf08 project page.

Reported by Fixed by
  • kong, the theme maintainer
Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-139 - PDFThumb OS Injection

Drupal Contrib Security Announcements - Wed, 09/12/2012 - 17:03
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-139
  • Project: PDFThumb (third-party module)
  • Version: 7.x
  • Date: 2012-September-12
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: OS Injection
Description

PDFThumb module creates thumbnail images of PDF files.
The module doesn't sufficiently escape user-entered values when executing commands on the server allowing an attacker to execute whatever commands are available to the web server user (e.g. www-data).
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer PDFThumb".

CVE: Requested

Versions affected
  • PDFThumb 7.x-1.x versions prior to 7.x-1.1

Drupal core is not affected. If you do not use the contributed PDFThumb module, there is nothing you need to do.

Solution

Install the latest version:

Also see the PDFThumb project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-138 - Exposed Filter Data - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 09/05/2012 - 19:29
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-138
  • Project: Exposed Filter Data (third-party module)
  • Version: 6.x
  • Date: 2012-September-05
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

The Exposed Filter Data facilitates displaying data posted to Views via an exposed filter. The module does not properly sanitize user-supplied data prior to output, leading to a Cross-Site Scripting (XSS) vulnerability.

CVE: Requested

Versions affected
  • Exposed Filter Data 6.x-1.x versions prior to 6.x-1.2.

Drupal core is not affected. If you do not use the contributed Exposed Filter Data module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Exposed Filter Data module for Drupal 6.x, upgrade to Exposed Filter Data 6.x-1.2.
  • The 7.x-1.x branch is not vulnerable. If you use Exposed Filter Data for Drupal 7.x, there is nothing you need to do.

Also see the Exposed Filter Data project page.

Reported by Fixed by Coordinated by
  • Michael Hess (mlhess) of the Drupal Security Team
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-137 - Heartbeat - Cross Site Request Forgery (CSRF) in heartbeat_comments

Drupal Contrib Security Announcements - Wed, 09/05/2012 - 17:46
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-137
  • Project: Heartbeat (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-September-5
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery
Description

This module enables you to display activity for events on a site.
The module doesn't sufficiently check the heartbeat comment post values making it possible for an attacker to cause a user to unknowingly make comments.

CVE: Requested

Versions affected
  • heartbeat_comments 6.x-4.x versions prior to 6.x-4.11.
  • heartbeat_comments 7.x-1.x versions prior to 7.x-1.0.

Drupal core is not affected. If you do not use the contributed Heartbeat module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the heartbeat_comments or shouts module for Drupal 6.x, upgrade to heartbeat 6.x-4.12
  • If you use the heartbeat_comments module for Drupal 7.x, upgrade to heartbeat 7.x-1.1

Also see the Heartbeat project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-136 - Apache Solr Search Autocomplete - Cross Site Scripting (XSS)

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 21:12
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-136
  • Project: Apache Solr Autocomplete (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-August-29
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Description

Apache Solr Search Autocomplete module enables you to add autocomplete capabilities to the search text field for the Apache Solr Search Integration module.

The module doesn't sufficiently filter the autocomplete results sent back from the Drupal site, so under the scenario where someone provided a URL with a specially-crafted search string embedded in it, the attacker could have a user execute arbitrary Javascript when clicking or focusing on the autocomplete text field.

This vulnerability is mitigated by the fact that the attacked user must click or otherwise give focus to the text widget to have the Javascript activate.

CVE: Requested

Versions affected
  • Apache Solr Autocomplete 6.x-1.x versions prior to 6.x-1.4.
  • Apache Solr Autocomplete 7.x-1.x versions prior to 7.x-1.3.

Drupal core is not affected. If you do not use the contributed Apache Solr Autocomplete module, there is nothing you need to do.

Solution

Install the latest version.

Also see the Apache Solr Autocomplete project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-135 - CAPTCHA - Insufficient anti-automation prevention

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 18:23
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-135
  • Project: CAPTCHA (third-party module)
  • Version: 6.x
  • Date: 2011-August-29
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Description

This module enables you to protect website forms using a CAPTCHA. A CAPTCHA is a test which attempts to differentiate between a human and an automated bot or script.

The module doesn't ensure that test submissions have a single-use unique token. This means that web robots could reuse a single successful submission multiple times, reducing the effectiveness of the protection.

CVE: Requested

Versions affected
  • CAPTCHA 6.x-2.x versions prior to 6.x-2.3

Drupal core is not affected. If you do not use the contributed CAPTCHA module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the CAPTCHA module for Drupal 6.x, upgrade to CAPTCHA 6.x-2.3 or greater

Also see the CAPTCHA project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-134 - Views - Privilege Escalation

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 18:20
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-134
  • Project: (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Privilege escalation
Description

The Views module provides a flexible method for Drupal site designers to control how lists and tables of content, users, taxonomy terms and other data are presented.

The module incorrectly modifies the global user object in some situations when a view has a uid argument and performs validation on that argument.

This vulnerability is mitigated by the fact that it only affects sites with more roles than default where a role with a low role ID has more privileges than other roles on the site and where untrusted (i.e. potentially malicious) users are granted several of those roles.

CVE: Requested

Versions affected
  • Views 6.x-2.x versions prior to 6.x-2.16.

Drupal core is not affected. If you do not use the contributed module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Views module for Drupal 6.x, upgrade to Views 6.x-2.16

Also see the project page.

Reported by Fixed by
  • Derek Wright one of module maintainers, also of the Drupal Security Team
Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-133 - Taxonomy Image - Cross Site Scripting (XSS) & Arbitrary PHP code execution

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 18:10
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-133
  • Project: Taxonomy Image (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Arbitrary PHP code execution
Description

The taxonomy_image module allows site administrators to associate images with taxonomy terms.

The module did not sufficiently filter retrieval of taxonomy images, allowing users to bypass Drupal's normal file upload protections to install malicious HTML or executable code to the server.

This vulnerability is mitigated by the fact that an attacker must have the permissions "administer taxonomy" and "administer taxonomy images", and that the fix for SA-2006-006 - Drupal Core - Execution of arbitrary files in certain Apache configurations should prevent code execution in typical Apache configurations.

CVE: Requested

Versions affected
  • Taxonomy Image 6.x-1.x versions prior to 6.x-1.7.

Drupal core is not affected. If you do not use the contributed Taxonomy Image module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Taxonomy Image project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-132 - Announcements - Access Bypass

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 18:05
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-132
  • Project: Announcements (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Description

The Announcements module creates an "announcement" content type and provides both node views and block lists.

The module doesn't sufficiently check node access under certain conditions.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access announcements".

CVE: Requested

Versions affected
  • Announcements 6.x-1.x versions prior to 6.x-1.5.

Drupal core is not affected. If you do not use the contributed Announcements module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Announcements project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-131 - Email Field - Access Bypass

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 18:02
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-131
  • Project: Email Field (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-August-29
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Description

The email module provides a field type (CCK / FieldAPI) for storing email addresses. Furthermore, it provides a formatter to output the email address as a link to a contact form. The contact form formatter allows a site visitor to email the stored address without letting them see what that e-mail address is.

The module didn't sufficiently check access for the contact form page, allowing a site visitor to email the stored address on the entity without having access to the entity itself.

CVE: Requested

Versions affected
  • Email Field 6.x-1.x versions prior to 6.x-1.2.
  • Email Field 7.x-1.x versions prior to 7.x-1.1.

Drupal core is not affected. If you do not use the contributed Email Field module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Email Field project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

SA-CONTRIB-2012-130 - Jstool - Multiple Vulnerabilities

Drupal Contrib Security Announcements - Wed, 08/29/2012 - 15:01
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-130
  • Project: Javascript Tool (third-party module)
  • Version: 7.x
  • Date: 2012-August-29
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities
Description

Javascript Tool enables administrators to edit any javascript file online from an admin panel.

The module does not protect its menu paths, which contain sensitive information about all javascript files on the site and their contents.
The module does not validate filenames which can lead to potential read/write access to arbitrary files on the server.

Write access to files is mitigated by the fact that an attacker must have the permission to use the full_html text format.

CVE: Requested

Versions affected
  • Javascript Tool 7.x-1.x versions prior to 7.x-1.7.

Drupal core is not affected. If you do not use the contributed Javascript Tool module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Javascript Tool project page.

Reported by Fixed by Coordinated by Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Categories: Security posts

Pages