drupal-6.34-1.AXS3

エラータID: AXSA:2014-817:05

Release date: 
Friday, December 5, 2014 - 15:44
Subject: 
drupal-6.34-1.AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

Description:

Drupal is a free software package that allows an individual or a
community of users to easily publish, manage and organize a wide variety
of content on a website. Tens of thousands of people and organizations
have used Drupal to power scores of different web sites, including

* Community web portals
* Discussion sites
* Corporate web sites
* Intranet applications
* Personal web sites or blogs
* Aficionado sites
* E-commerce applications
* Resource directories
* Social Networking sites

Security issues fixed with this release:

Session hijacking (Drupal 6 and 7)

A specially crafted request can give a user access to another user's session, allowing an attacker to hijack a random session.

This attack is known to be possible on certain Drupal 7 sites which serve both HTTP and HTTPS content ("mixed-mode"), but it is possible there are other attack vectors for both Drupal 6 and Drupal 7.

CVE identifier hasn't been requested by Drupal yet.

https://www.drupal.org/SA-CORE-2014-006

Solution: 

Update package.

Additional Info: 

N/A

Download: 

SRPMS
  1. drupal-6.34-1.AXS3.src.rpm
    MD5: 995bed1d3938cf6492265fc644de2023
    SHA-256: e1fcb300e53a35067ebb405535ec309e6ac1a06240a1365913b098c5f4ab59eb
    Size: 1.91 MB

Asianux Server 3 for x86
  1. drupal-6.34-1.AXS3.noarch.rpm
    MD5: 211ee4d927afe2243e51802105ea20ca
    SHA-256: d88359d0e597b170eb6c4be42571130671f731b8193179a8fd537f8dbfa631db
    Size: 1.89 MB

Asianux Server 3 for x86_64
  1. drupal-6.34-1.AXS3.noarch.rpm
    MD5: bee714edaf90a9004445194100ff7455
    SHA-256: 41bca377e580796692b715c0f8588f3cec7255fbcfc478fa0d737c3dc2cd55e2
    Size: 1.89 MB