drupal-6.28-4.AXS3

エラータID: AXSA:2013-681:02

Release date: 
Monday, November 25, 2013 - 13:39
Subject: 
drupal-6.28-4.AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
Low
Description: 

Description Drupal is a free software package that allows an individual or a community of users to easily publish, manage and organize a wide variety of content on a website. Tens of thousands of people and organizations have used Drupal to power scores of different web sites, including

• Community web portals
• Discussion sites
• Corporate web sites
• Intranet applications
• Personal web sites or blogs
• Aficionado sites
• E-commerce applications
• Resource directories
• Social Networking sites

Security issues fixed with this issue (from www.drupal.org):

This is a public service announcement regarding possible insertion of hidden links in comments using core CSS selectors within filtered HTML Text formats ("Input formats" in Drupal 6). Drupal core provides several CSS selectors that, by design, hide elements on the page. Using these selectors it is possible to create links to third-party websites that are hidden within a comment. This technique has been observed on live production websites.

Drupal core provides mechanisms that sanitize user submitted links by adding a rel="nofollow" attribute. This feature can be enabled for Drupal 7 sites at admin/config/content/formats/filtered_html and for Drupal 6 sites at admin/settings/filters/1/configure. Note that these paths are for the default formats provided with core. Your site may define custom formats which should be reviewed and updated as well.

Careful moderation of user submitted comments is always advised. Additionally, automated comment moderation tools may help to mitigate and flag these malicious comment submissions.

Solution

Review user-submitted content on your site to see if untrusted users have posted content that includes classes. Review those classes to see if they will hide unwanted content.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. drupal-6.28-4.AXS3.src.rpm
    MD5: 6529abf6a823e4babf4bddbe96e798c0
    SHA-256: b1d934946a082ffd25d3268a0714fae58e0ec7be0aed5fd9069f09c233033538
    Size: 1.90 MB