SB2015092622 - Debian update for drupal7
Published: September 26, 2015
Security Bulletin ID
SB2015092622
Severity
Low
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Impersonation (CVE-ID: CVE-2014-1475)
The vulnerability allows a remote user to hijack valid user's account.The weakness is caused by OpenID module and allows a malicious user to log in under the name of another user (even administrator's) on the site and steal accounts.
Successful exploitation of this vulnerability may allow a remote attacker to hijack target user's account.
2) Access bypass (CVE-ID: CVE-2014-1476)
The vulnerability allows a remote user to read a potentially sensitive data.The weakness exists due to emersion of unpublished content in the lists of Taxonomy or Custom modules that opens data for users not allowed to see it before.
Successful exploitation of the vulnerability may allow attackers to get potentially sensitive data.
Remediation
Install update from vendor's website.