drupal-6.4-5AXS3
エラータID: AXSA:2009-16:01
Drupal is a free software package that allows an individual or a community of users to easily publish, manage and organize a wide variety of content on a website.
Fixed bugs:
- Access Bypass
The Content Translation module for Drupal 6.x enables users to make a translation of an existing item of content (a node). In that process the existing node's content is copied into the new node's submission form.
The module contains a flaw that allows a user with the 'translate content' permission to potentially bypass normal viewing access restrictions, for example allowing the user to see the content of unpublished nodes even if they do not have permission to view unpublished nodes.
This issue only affects Drupal 6.x.
- Validation Bypass
When user profile pictures are enabled, the default user profile validation function will be bypassed, possibly allowing invalid user names or e-mail addresses to be submitted.
This issue only affects Drupal 6.x.
- Hardening against SQL injection
A parameter passed into the node access API was not properly escaped or validated before being used in SQL queries. While there is no direct risk of SQL injection from Drupal core, it's possible that this could have presented a risk in combination with a contributed module. Additional validation has been added to eliminate this risk.
This issue affects both Drupal 5.x and Drupal 6.x.
Update packages
N/A
SRPMS
- drupal-6.4-5AXS3.src.rpm
MD5: f974df7241be96b7a3668a72fd2f07ed
SHA-256: 383567a92aa6963691811ef50376a287d30b4a280b7342981d2726a1fb16b9c3
Size: 1.87 MB
Asianux Server 3 for x86
- drupal-6.4-5AXS3.noarch.rpm
MD5: 5c54b459819fb2f712117b774c032ece
SHA-256: 704aa4930e2dbabe0e0b182f7a06d48ac6fcd9b32ae74caed3a54605c33e37ca
Size: 1.93 MB
Asianux Server 3 for x86_64
- drupal-6.4-5AXS3.noarch.rpm
MD5: 90c00d6f1efaa3797e4c4e9d4517e017
SHA-256: d50ed8985fc988eafed6f1a2c5b8c6f2f251e1a2fe3e837ba4924b027e982a2f
Size: 1.93 MB