SB2016111904 - Arch Linux update for drupal



SB2016111904 - Arch Linux update for drupal

Published: November 19, 2016 Updated: May 3, 2017

Security Bulletin ID SB2016111904
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2016-9449)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.


2) Insufficient verification of data authenticity (CVE-ID: CVE-2016-9450)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.


3) Input validation error (CVE-ID: CVE-2016-9452)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.


Remediation

Install update from vendor's website.