Bug 888990 (CVE-2012-5651, CVE-2012-5652, CVE-2012-5653)

Summary: CVE-2012-5651 CVE-2012-5652 CVE-2012-5653 drupal: multiple flaws fixed in 6.27/7.18 (SA-CORE-2012-004)
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gwync, jlieskov, peter.borsa, stickster, sven
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-01-07 09:11:16 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 888991, 888992, 888993, 888994    
Bug Blocks:    

Description Vincent Danen 2012-12-19 23:43:41 UTC
Upstream Drupal has reported SA-CORE-2012-004 [1] which corrects multiple vulnerabilities:

1) Access bypass (User module search - Drupal 6 and 7)
2) Access bypass (Upload module - Drupal 6)
3) Arbitrary PHP code execution (File upload modules - Drupal 6 and 7)

CVEs have been requested and are not yet assigned.

These flaws have been fixed in Drupal 6.27 and 7.18.

[1] http://drupal.org/SA-CORE-2012-004

Comment 1 Vincent Danen 2012-12-19 23:47:16 UTC
Created drupal7 tracking bugs for this issue

Affects: fedora-all [bug 888993]
Affects: epel-all [bug 888994]

Comment 2 Vincent Danen 2012-12-19 23:47:18 UTC
Created drupal6 tracking bugs for this issue

Affects: fedora-all [bug 888991]
Affects: epel-all [bug 888992]

Comment 3 Vincent Danen 2012-12-20 17:37:50 UTC
CVE assignments as per:

http://www.openwall.com/lists/oss-security/2012/12/20/1

CVE-2012-5651: Access bypass (User module search - Drupal 6 and 7)

CVE-2012-5652: Access bypass (Upload module - Drupal 6)

CVE-2012-5653: Arbitrary PHP code execution (File upload modules - Drupal 6 and 7)

Comment 5 Fedora Update System 2013-01-04 19:39:22 UTC
drupal6-6.27-1.el6, drupal7-7.18-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2013-01-04 19:43:17 UTC
drupal6-6.27-1.el5, drupal7-7.18-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2013-01-05 06:35:36 UTC
drupal6-6.27-1.fc17, drupal7-7.18-1.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2013-01-05 06:36:21 UTC
drupal6-6.27-1.fc16, drupal7-7.18-1.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.