[SECURITY] [DSA 1930-1] New drupal6 packages fix several vulnerabilities

Debian Security Advisory DSA-1930-1                  security@debian.org
http://www.debian.org/security/                      Steffen Joeris
November 07, 2009                   http://www.debian.org/security/faq
Package        : drupal6                           
Vulnerability  : several vulnerabilities           
Problem type   : remote                            
Debian-specific: no                                
CVE IDs        : CVE-2009-2372 CVE-2009-2373 CVE-2009-2374
Debian Bug     : 535435 547140                            

Several vulnerabilities have been found in drupal6, a fully-featured
content management framework. The Common Vulnerabilities and Exposures
project identifies the following problems:


Gerhard Killesreiter discovered a flaw in the way user signatures are
handled. It is possible for a user to inject arbitrary code via a
crafted user signature. (SA-CORE-2009-007)


Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site
scripting issue in the forum module, which could be exploited via the
tid parameter. (SA-CORE-2009-007)


Sumit Datta discovered that certain drupal6 pages leak sensible
information such as user credentials. (SA-CORE-2009-007)

Several design flaws in the OpenID module have been fixed, which could
lead to cross-site request forgeries or privilege escalations. Also, the
file upload function does not process all extensions properly leading
to the possible execution of arbitrary code.

For the stable distribution (lenny), these problems have been fixed in
version 6.6-3lenny3.

The oldstable distribution (etch) does not contain drupal6.

For the testing distribution (squeeze) and the unstable distribution
(sid), these problems have been fixed in version 6.14-1.

We recommend that you upgrade your drupal6 packages.

Debian GNU/Linux 5.0 alias lenny
- --------------------------------

Debian (stable)
- ---------------

Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Reply to: