Bug 717874 (CVE-2011-2687) - CVE-2011-2687 Remote access bypass vulnerability in Drupal 7
Summary: CVE-2011-2687 Remote access bypass vulnerability in Drupal 7
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-2687
Product: Fedora
Classification: Fedora
Component: drupal7
Version: 15
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Gwyn Ciesla
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-06-30 09:19 UTC by Othman Madjoudj
Modified: 2011-07-18 18:34 UTC (History)
3 users (show)

Fixed In Version: drupal7-7.4-1.el6
Clone Of:
Environment:
Last Closed: 2011-07-16 07:25:39 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Othman Madjoudj 2011-06-30 09:19:12 UTC
Advisory ID: DRUPAL-SA-CORE-2011-002
Project: Drupal core
Version: 7.x
Date: 2011-JUNE-29
Security risk: Highly critical
Exploitable from: Remote
Vulnerability: Access bypass

Details:
http://drupal.org/node/1204582

Solution:
Update to Drupal 7.4

Comment 1 Elad Alfassa 2011-06-30 12:10:13 UTC
Changing priority to urgent.



-- 
Fedora Bugzappers volunteer triage team
https://fedoraproject.org/wiki/BugZappers

Comment 2 Gwyn Ciesla 2011-06-30 12:26:10 UTC
Working on it at this very moment. . .

Comment 3 Fedora Update System 2011-06-30 13:03:08 UTC
drupal7-7.4-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/drupal7-7.4-1.el6

Comment 4 Fedora Update System 2011-06-30 13:03:22 UTC
drupal7-7.4-1.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/drupal7-7.4-1.fc14

Comment 5 Fedora Update System 2011-06-30 13:03:35 UTC
drupal7-7.4-1.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/drupal7-7.4-1.fc15

Comment 6 Fedora Update System 2011-06-30 13:03:48 UTC
drupal7-7.4-1.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/drupal7-7.4-1.el5

Comment 7 Fedora Update System 2011-06-30 17:52:05 UTC
Package drupal7-7.4-1.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing drupal7-7.4-1.el6'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/drupal7-7.4-1.el6
then log in and leave karma (feedback).

Comment 8 Jan Lieskovsky 2011-07-11 10:45:43 UTC
CVE Request:
http://www.openwall.com/lists/oss-security/2011/07/11/2

Comment 9 Jan Lieskovsky 2011-07-15 08:34:19 UTC
The CVE identifier of CVE-2011-2687 has been assigned to this issue:
http://www.openwall.com/lists/oss-security/2011/07/12/16

Comment 10 Fedora Update System 2011-07-16 07:25:29 UTC
drupal7-7.4-1.fc14 has been pushed to the Fedora 14 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2011-07-16 07:29:47 UTC
drupal7-7.4-1.fc15 has been pushed to the Fedora 15 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2011-07-18 18:32:28 UTC
drupal7-7.4-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2011-07-18 18:34:26 UTC
drupal7-7.4-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.