FreeBSD : drupal -- multiple vulnerabilities (6d85dc62-f2bd-11dd-9f55-0030843d3802)

This script is Copyright (C) 2009-2013 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing one or more security-related
updates.

Description :

Drupal Team reports :

The Content Translation module for Drupal 6.x enables users to make a
translation of an existing item of content (a node). In that proces
the existing node's content is copied into the new node's submission
form.

The module contains a flaw that allows a user with the 'translate
content' permission to potentially bypass normal viewing access
restrictions, for example allowing the user to see the content of
unpublished nodes even if they do not have permission to view
unpublished nodes.

When user profile pictures are enabled, the default user profile
validation function will be bypassed, possibly allowing invalid user
names or e-mail addresses to be submitted.

See also :

http://drupal.org/node/358957
http://www.nessus.org/u?76b358b9

Solution :

Update the affected packages.

Risk factor :

High

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 35584 (freebsd_pkg_6d85dc62f2bd11dd9f550030843d3802.nasl)

Bugtraq ID:

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now