[41454] in bugtraq

home help back first fref pref prev next nref lref last post

[DRUPAL-SA-2005-008] Drupal 4.6.4 / 4.5.6 fixes XSS and HTTP header injection issue

daemon@ATHENA.MIT.EDU (Uwe Hermann)
Thu Dec 1 19:30:15 2005

Date: Thu, 1 Dec 2005 16:45:58 +0100
From: Uwe Hermann <uwe@hermann-uwe.de>
To: bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk,
        phpsec@phparch.com
Message-ID: <20051201154558.GB18510@aragorn>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="XOIedfhf+7KOe/yw"
Content-Disposition: inline


--XOIedfhf+7KOe/yw
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

----------------------------------------------------------------------------
Drupal security advisory                                  DRUPAL-SA-2005-008
----------------------------------------------------------------------------
Advisory ID:    DRUPAL-SA-2005-008
Project:        Drupal core
Date:           2005-11-30
Security risk:  less critical
Impact:         normal
Where:          from remote
Vulnerability:  XSS, HTTP header injection
----------------------------------------------------------------------------

Description
-----------
Paul Laudanski informed us that it's possible to attach files that are able
to run Javascript under Internet Explorer.

Further investigation of the problem revealed that the same method can be
used to inject arbitrary HTTP headers.

Versions affected
-----------------
Drupal 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5
Drupal 4.6.0, 4.6.1, 4.6.2, 4.6.3

Solution
--------
- If you are running Drupal 4.5.x, then upgrade to Drupal 4.5.6.
- If you are running Drupal 4.6.x, then upgrade to Drupal 4.6.4.

Contact
-------
The security contact for Drupal can be reached at security at drupal.org
or using the form at http://drupal.org/contact.
More information is available from http://drupal.org/security or from
our security RSS feed http://drupal.org/security/rss.xml.


// Uwe Hermann, on behalf of the Drupal Security Team.
--=20
Uwe Hermann <uwe@hermann-uwe.de>
http://www.hermann-uwe.de                 | http://www.crazy-hacks.org
http://www.it-services-uh.de              | http://www.phpmeat.org
http://www.unmaintained-free-software.org | http://www.holsham-traders.de

--XOIedfhf+7KOe/yw
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDjxq2XdVoV3jWIbQRAvhYAJwJy7+/kXu1T77qbTrL99q3z7XXEwCfceme
gaguJLYHnL3QynIywcA4VUc=
=LI6H
-----END PGP SIGNATURE-----

--XOIedfhf+7KOe/yw--

home help back first fref pref prev next nref lref last post