SB2015092622 - Debian update for drupal7



SB2015092622 - Debian update for drupal7

Published: September 26, 2015

Security Bulletin ID SB2015092622
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Impersonation (CVE-ID: CVE-2014-1475)

The vulnerability allows a remote user to hijack valid user's account.
The weakness is caused by OpenID module and allows a malicious user to log in under the name of another user (even administrator's) on the site and steal accounts.
Successful exploitation of this vulnerability may allow a remote attacker to hijack target user's account.

2) Access bypass (CVE-ID: CVE-2014-1476)

The vulnerability allows a remote user to read a potentially sensitive data.
The weakness exists due to emersion of unpublished content in the lists of Taxonomy or Custom modules that opens data for users not allowed to see it before.
Successful exploitation of the vulnerability may allow attackers to get potentially sensitive data.

Remediation

Install update from vendor's website.