Bug 1255662 (CVE-2015-6658, CVE-2015-6659, CVE-2015-6660, CVE-2015-6661, CVE-2015-6665)

Summary: CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003)
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ccoleman, dmcphers, gwync, jialiu, joelsmith, jokerman, jsmith.fedora, lmeyer, mmccomas, peter.borsa, stickster, sven
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: drupal6-6.37,drupal7-7.39 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-05-20 21:15:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1255671, 1255672, 1255673, 1255674, 1255675    
Bug Blocks:    

Description Adam Mariš 2015-08-21 09:34:41 UTC
Several issues were fixed in Drupal 6.37 and Drupal 7.39 core modules:

  Cross-site Scripting (Ajax system - Drupal 7): CVE-2015-6665
  Cross-site Scripting (Autocomplete system - Drupal 6 and 7): CVE-2015-6658
  SQL Injection (Database API - Drupal 7): CVE-2015-6659
  Cross-site Request Forgery (Form API - Drupal 6 and 7): CVE-2015-6660
  Information Disclosure (Access system - Drupal 6 and 7): CVE-2015-6661

External reference:

https://www.drupal.org/SA-CORE-2015-003

Comment 2 Adam Mariš 2015-08-21 09:44:13 UTC
Created drupal7 tracking bugs for this issue:

Affects: fedora-all [bug 1255672]
Affects: epel-all [bug 1255674]

Comment 3 Adam Mariš 2015-08-21 09:44:15 UTC
Created drupal6 tracking bugs for this issue:

Affects: fedora-all [bug 1255671]
Affects: epel-all [bug 1255673]

Comment 4 Fedora Update System 2015-09-06 01:10:26 UTC
drupal6-6.37-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2015-09-06 04:49:58 UTC
drupal6-6.37-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2015-09-06 06:20:28 UTC
drupal6-6.37-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2015-09-06 17:05:23 UTC
drupal6-6.37-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2015-09-13 20:19:57 UTC
drupal6-6.37-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2015-09-14 01:24:47 UTC
drupal6-6.37-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.

Comment 10 Product Security DevOps Team 2020-05-20 21:15:35 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.