drupal-6.30-1.AXS3
エラータID: AXSA:2014-234:01
Drupal is a free software package that allows an individual or a community of users to easily publish, manage and organize a wide variety of content on a website. Tens of thousands of people and organizations have used Drupal to power scores of different web sites, including:
• Community web portals
• Discussion sites
• Corporate web sites
• Intranet applications
• Personal web sites or blogs
• Aficionado sites
• E-commerce applications
• Resource directories
• Social Networking sites
Security issues fixed with this release:
• CVE-2014-1475
The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.
• CVE-2013-6385
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
• CVE-2013-6386
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
Update packages.
The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
N/A
SRPMS
- drupal-6.30-1.AXS3.src.rpm
MD5: 9fca0f7a81b112417795b97445f2060f
SHA-256: 46764f07f3a48b432da10411751cb41651be83ec336684f052ea680963369216
Size: 1.90 MB
Asianux Server 3 for x86
- drupal-6.30-1.AXS3.noarch.rpm
MD5: 3a9c4989d5750bfaf70af45ca47f3d4a
SHA-256: a0ca4abe0c0a4588f118e6b8befad3a65e4735043d624a91cfec47023b6a8c96
Size: 1.89 MB
Asianux Server 3 for x86_64
- drupal-6.30-1.AXS3.noarch.rpm
MD5: ac903b8c122052b12e30cdceb20689fe
SHA-256: a72cca4079bf8a6b48411b690bf38585700be1a94c1f001b3f2cf86eca287fed
Size: 1.89 MB