[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1004-1] drupal7 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : drupal7
Version        : 7.14-2+deb7u16
CVE ID         : CVE-2017-6922

Private files that have been uploaded by an anonymous user but not permanently
attached to content on the site should only be visible to the anonymous user
that uploaded them, rather than all anonymous users. Drupal core did not
previously provide this protection, allowing an access bypass vulnerability to
occur. This issue is mitigated by the fact that in order to be affected, the
site must allow anonymous users to upload files into a private file system. 

For Debian 7 "Wheezy", these problems have been fixed in version
7.14-2+deb7u16.

We recommend that you upgrade your drupal7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEjtbD+LrJ23/BMKhw+COicpiDyXwFAllT0DYACgkQ+COicpiD
yXyNYw//TMhWtAnT9XQVOSNgXIEM/0Gy4CNe6YEFuasrUE7P1G79bKdeX2OT18ur
IcaGWbsYwqy9eZLCUmYCtlmkvnvhzjK9McA/dMTnGlLUzRbKyum1fS4pJTlkjsBk
yvC5NQ7Yj7GB8nPH0/4SzqclrrDV2wth0luYM0oSU4uF0bB57N7h/fXdNuX6uogH
y1LL9O5RqySjeSgSHHwxDiqp6A+eNZU8gTr6eX/zRaMoBrzX3pO1DUYX0gM0Sa9K
HoalLIlARWbDiJxciEaiLma+uIaLF34D1h5zisH+URU3HqUz34xoe91gaN2EqC5O
A6q22WtIzmszb8jefUd1fs3i8CNdxCOwFO0c2gOAdGc5T7ExZoILwbU+OhZ53qNZ
1kHLQZHnFYgNlaw1c8JbEKaOU/xqNLSwMd+l6fvBnsuSEnauqCg0uwsRtHhROjm+
aiORwOcsUj28XUPOWoQywzvJX6OuboSrEYBifaNndS8Wk4uxU7xkVRy4R6y3l0Kr
5sJxcg7ZfnQ5aHc8qbvxbB7/ZugVHhFSvOHJ8q7+jblND/EIKIVT7Q1bcoXaArY7
0d/sLvrtzNcummWQgduVXpbqEPZNpVLLkAmM5GgsFnLyKRbXx1V4dm3aOVkfVyGp
+d/dvCIbi/2gzImMNDGqE3KsuTuZEBJUA/uvQwP8YrGPHnKcl8A=
=3ryC
-----END PGP SIGNATURE-----


Reply to: