Fedora 10 : drupal-date-6.x.2.3-0.fc10 (2009-8162)

This script is Copyright (C) 2009-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

- Advisory ID: DRUPAL-SA-CONTRIB-2009-046 * Project: Date
(third-party module) * Version: 6.x * Date: 2009-July-29
* Security risk: Moderately critical * Exploitable from:
Remote * Vulnerability: Cross Site Scripting --------
DESCRIPTION
--------------------------------------------------------
- The Date module provides a date CCK field that can be
added to any content type. The Date Tools module that is
bundled with Date module does not properly escape user
input when displaying labels for fields on a content
type. A malicious user with the 'use date tools'
permission of the Date Tools sub- module, or the
'administer content types' permission could attempt a
cross site scripting [1] (XSS) attack when creating a
new content type, leading to the user gaining full
administrative access. -------- VERSIONS AFFECTED
--------------------------------------------------- *
Date for Drupal 6.x prior to 6.x-2.3 Drupal core is not
affected. If you do not use the contributed Date module,
there is nothing you need to do. -------- SOLUTION
--------------------------------------------------------
---- Upgrade to the latest version: * If you use Date
for Drupal 6.x upgrade to Date 6.x-2.3 [2] Note that the
'use date tools' permission has been renamed as
'administer date tools' to clarify that this is an
administrative permission (it allows the creation of new
content types via a wizard form). You will need to
re-assign this permission to any roles that were using
it. See also the Date project page [3]. --------
REPORTED BY
--------------------------------------------------------
- Stella Power [4] of the Drupal Security Team --------
FIXED BY
--------------------------------------------------------
---- Stella Power [5] and Karen Stevenson [6], the
project maintainer. -------- CONTACT
--------------------------------------------------------
----- The security contact for Drupal can be reached at
security at drupal.org or via the form at
http://drupal.org/contact. [1]
http://en.wikipedia.org/wiki/Cross-site_scripting [2]
http://drupal.org/node/534332 [3]
http://drupal.org/project/date [4]
http://drupal.org/user/66894 [5]
http://drupal.org/user/66894 [6]
http://drupal.org/user/45874

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://drupal.org/node/534332
http://drupal.org/project/date
http://en.wikipedia.org/wiki/Cross-site_scripting
http://www.nessus.org/u?31807578

Solution :

Update the affected drupal-date package.

Risk factor :

Low / CVSS Base Score : 2.1
(CVSS2#AV:N/AC:H/Au:S/C:N/I:P/A:N)
CVSS Temporal Score : 1.8
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Fedora Local Security Checks

Nessus Plugin ID: 40455 (fedora_2009-8162.nasl)

Bugtraq ID: 35790

CVE ID: CVE-2009-3156

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now