Debian DSA-1792-1 : drupal6 - multiple vulnerabilities

medium Nessus Plugin ID 38702

Synopsis

The remote Debian host is missing a security-related update.

Description

Multiple vulnerabilities have been discovered in drupal, a web content management system. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2009-1575 pod.Edge discovered a cross-site scripting vulnerability due that can be triggered when some browsers interpret UTF-8 strings as UTF-7 if they appear before the generated HTML document defines its Content-Type. This allows a malicious user to execute arbitrary JavaScript in the context of the website if they're allowed to post content.

- CVE-2009-1576 Moritz Naumann discovered an information disclosure vulnerability. If a user is tricked into visiting the site via a specially crafted URL and then submits a form (such as the search box) from that page, the information in their form submission may be directed to a third-party site determined by the URL and thus disclosed to the third-party. The third-party site may then execute a cross-site request forgery attack against the submitted form.

Solution

Upgrade the drupal6 package.

The old stable distribution (etch) does not contain drupal and is not affected.

For the stable distribution (lenny), these problems have been fixed in version 6.6-3lenny1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526378

https://security-tracker.debian.org/tracker/CVE-2009-1575

https://security-tracker.debian.org/tracker/CVE-2009-1576

https://www.debian.org/security/2009/dsa-1792

Plugin Details

Severity: Medium

ID: 38702

File Name: debian_DSA-1792.nasl

Version: 1.16

Type: local

Agent: unix

Published: 5/8/2009

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:drupal6, cpe:/o:debian:debian_linux:5.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 5/6/2009

Reference Information

CVE: CVE-2009-1575, CVE-2009-1576

BID: 34779

CWE: 79

DSA: 1792