NavigationUser login |
[Security announcements] Drupal core - Arbitrary code execution![]() Just to let you know; Of course redhat.at is already updated! ------------DRUPAL CORE - ARBITRARY CODE EXECUTION------------ * Advisory ID: DRUPAL-SA-2007-005 * Project: Drupal core * Version: 4.7.x, 5.x * Date: 2007-Jan-29 * Security risk: Highly critical * Exploitable from: Remote * Vulnerability: Arbitrary code execution ------------DESCRIPTION------------ Previews on comments were not passed through normal form validation routines, Immediate workarounds include: disabling the comment module, revoking the 'post ------------VERSIONS AFFECTED------------ * Drupal 4.7.x before version 4.7.6. * Drupal 5.x before version 5.1. ------------SOLUTION------------ Install the latest version: * Drupal 4.7.6 * Drupal 5.1 * To patch Drupal 4.7.5 use SA-2007-005-4.7.5.patch * To patch Drupal 5.0 use SA-2007-005-5.0.patch ------------REPORTED BY------------ The Drupal security team. ------------CONTACT------------ The security contact for Drupal can be reached at security at drupal.org or via |
Similar entriesBloggersWho's new
Who's onlineThere are currently 0 users and 46 guests online.
SearchRecent blog posts
|