Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 20th, 2012, 08:52 GMT · By

BLOG

Drupal 7.18 and 6.28 Released to Address Security Vulnerabilities

SHARE:

Adjust text size:


Drupal 7.18 and 6.28 released Enlarge picture - Drupal 7.18 and 6.28 released
Drupal 7.18 and Drupal 6.27 have been released. Both of them are security releases meant to fix a number of vulnerabilities.

The updates address a couple of access bypass vulnerabilities and one arbitrary PHP code execution flaw. The security holes are considered to be moderately critical and they’re all remotely exploitable.

The first access bypass vulnerability, which affects the user module search, allows blocked users to appear in search results even if the results are viewed by an unprivileged customer. The issue impacts both Drupal 6.x and Drupal 7.x.

The second access bypass bug allows information about uploaded files to be displayed in RSS feeds and search results even for users who don’t have the “view uploaded files” permission. The problem impacts only Drupal 6.x customers.

The arbitrary PHP code execution can be exploited by a malicious user to name a file so that it bypasses the munging of the filename in the CMS’s input validation.

Users are advised to immediately apply these latest updates in order to fix the security problems.

Drupal is available for download here

TELL US WHAT YOU THINK:

1,537 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


MyBB 1.6.9 Security Release Available for Download

PayPal Rewards Researcher with $5,000 for Finding Remote Code Execution Flaw

One Critical, Three High Severity Vulnerabilities Fixed with Release of Chrome 23.0.1271.97

Gmail Phishing Scam: Account Update for Security Purposes

BlackHole Exploit Kit Has Difficulties in Infecting Chrome Users, Experts Say

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM