FreeBSD : drupal -- multiple vulnerabilities (6d85dc62-f2bd-11dd-9f55-0030843d3802)

high Nessus Plugin ID 35584

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Drupal Team reports :

The Content Translation module for Drupal 6.x enables users to make a translation of an existing item of content (a node). In that proces the existing node's content is copied into the new node's submission form.

The module contains a flaw that allows a user with the 'translate content' permission to potentially bypass normal viewing access restrictions, for example allowing the user to see the content of unpublished nodes even if they do not have permission to view unpublished nodes.

When user profile pictures are enabled, the default user profile validation function will be bypassed, possibly allowing invalid user names or e-mail addresses to be submitted.

Solution

Update the affected packages.

See Also

http://drupal.org/node/358957

http://www.nessus.org/u?d588825d

Plugin Details

Severity: High

ID: 35584

File Name: freebsd_pkg_6d85dc62f2bd11dd9f550030843d3802.nasl

Version: 1.13

Type: local

Published: 2/4/2009

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:drupal5, p-cpe:/a:freebsd:freebsd:drupal6, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2/4/2009

Vulnerability Publication Date: 1/14/2009

Reference Information

Secunia: 33500, 33542, 33550