drupal-6.30-1.AXS3

エラータID: AXSA:2014-234:01

Release date: 
Thursday, April 10, 2014 - 18:57
Subject: 
drupal-6.30-1.AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

Drupal is a free software package that allows an individual or a community of users to easily publish, manage and organize a wide variety of content on a website. Tens of thousands of people and organizations have used Drupal to power scores of different web sites, including:
• Community web portals
• Discussion sites
• Corporate web sites
• Intranet applications
• Personal web sites or blogs
• Aficionado sites
• E-commerce applications
• Resource directories
• Social Networking sites

Security issues fixed with this release:

• CVE-2014-1475
The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

• CVE-2013-6385
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

• CVE-2013-6386
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. drupal-6.30-1.AXS3.src.rpm
    MD5: 9fca0f7a81b112417795b97445f2060f
    SHA-256: 46764f07f3a48b432da10411751cb41651be83ec336684f052ea680963369216
    Size: 1.90 MB

Asianux Server 3 for x86
  1. drupal-6.30-1.AXS3.noarch.rpm
    MD5: 3a9c4989d5750bfaf70af45ca47f3d4a
    SHA-256: a0ca4abe0c0a4588f118e6b8befad3a65e4735043d624a91cfec47023b6a8c96
    Size: 1.89 MB

Asianux Server 3 for x86_64
  1. drupal-6.30-1.AXS3.noarch.rpm
    MD5: ac903b8c122052b12e30cdceb20689fe
    SHA-256: a72cca4079bf8a6b48411b690bf38585700be1a94c1f001b3f2cf86eca287fed
    Size: 1.89 MB