drupal-6.4-2AXS3

エラータID: AXSA:2008-463:04

Release date: 
Tuesday, November 11, 2008 - 14:25
Subject: 
drupal-6.4-2AXS3
Affected Channels: 
Asianux Server 3 for x86
Asianux Server 3 for x86_64
Severity: 
Moderate
Description: 

Drupal is a free software package that allows an individual or a community of users to easily publish, manage and organize a wide variety of content on a website.
Multiple vulnerabilities and weaknesses were discovered in Drupal.
File upload access bypass
A logic error in the core upload module validation allowed unprivileged users to attach files to content. This bug affects Drupal 6.x only.
Access rules bypass
A deficiency in the user module allowed users who had been blocked by access rules to continue logging into the site under certain conditions.
BlogAPI access bypass
The BlogAPI module does not implement correct validation for certain content fields, allowing for values to be set for fields which would otherwise be inaccessible on an internal Drupal form.
Versions affected
* Drupal 5.x before version 5.11
* Drupal 6.x before version 6.5

Solution: 

Update packages

Additional Info: 

N/A

Download: 

Asianux Server 3 for x86
  1. drupal-6.4-2AXS3.noarch.rpm
    MD5: 3b2c6eaa54534a0d81b0d5ac6e4ce849
    SHA-256: a270e3ee6f0ee8504ea702d7f614adaffb2e80091d489fa3972b528baf959070
    Size: 1.88 MB

Asianux Server 3 for x86_64
  1. drupal-6.4-2AXS3.noarch.rpm
    MD5: 39aa78f380c6f5ebf7b09fc157a4e83f
    SHA-256: 30db3a2b281927a07cf4b0777131a41528b13ea9ce06d1bf0e3f40513beda8c1
    Size: 1.88 MB