Fedora 11 : drupal-cck-6.x.2.7-1.fc11 (2010-10127)

This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

- Advisory ID: DRUPAL-SA-CONTRIB-2010-065
(http://drupal.org/node/829566) * Project: Content
Construction Kit (CCK) (third-party module) * Version:
5.x, 6.x * Date: 2010-June-16 * Security risk: Less
Critical * Exploitable from: Remote * Vulnerability:
Access Bypass -------- DESCRIPTION
--------------------------------------------------------
- The Content Construction Kit (CCK) project is a set of
modules that allows you to add custom fields to nodes
using a web browser. The CCK 'Node Reference' module can
be configured to display referenced nodes as hidden,
title, teaser or full view. Node access was not checked
when displaying these which could expose view access on
controlled nodes to unprivileged users. In addition,
Node Reference provides a backend URL that is used for
asynchronous requests by the 'autocomplete' widget to
locate nodes the user can reference. This was not
checking that the user had field level access to the
source field, allowing direct queries to the backend URL
to return node titles and IDs which the user would
otherwise be unable to access. Note that as Drupal 5 CCK
does not have any field access control functionality,
this issue only applies to the Drupal 6 version.
-------- VERSIONS AFFECTED
--------------------------------------------------- *
Content Construction Kit (CCK) module for Drupal 5.x
versions prior to 5.x-1.11 * Content Construction Kit
(CCK) module for Drupal 6.x versions prior to 6.x-2.7
Drupal core is not affected. If you do not use the
contributed Content Construction Kit (CCK) [1] module,
together with any node or field access module there is
nothing you need to do. -------- SOLUTION
--------------------------------------------------------
---- Install the latest version: * If you use the
Content Construction Kit (CCK) module for Drupal 5.x
upgrade to Content Construction Kit (CCK) 5.x-1.11 [2] *
If you use the Content Construction Kit (CCK) module for
Drupal 6.x upgrade to Content Construction Kit (CCK)
6.x-2.7 [3] See also the Content Construction Kit (CCK)
project page [4]. -------- REPORTED BY
--------------------------------------------------------
- * recrit [5] * Marc Ferran (markus_petrux) [6], module
co-maintainer -------- FIXED BY
--------------------------------------------------------
---- * Yves Chedemois (yched) [7], module co-maintainer
* Marc Ferran (markus_petrux) [8], module co-maintainer
* Karen Stevenson (KarenS) [9], module co- maintainer
-------- CONTACT
--------------------------------------------------------
----- The Drupal security team [10] can be reached at
security at drupal.org or via the form at
http://drupal.org/contact. * [1]
http://drupal.org/project/cck * [2]
http://drupal.org/node/828986 * [3]
http://drupal.org/node/828988 * [4]
http://drupal.org/project/cck * [5]
http://drupal.org/user/452914 * [6]
http://drupal.org/user/39593 * [7]
http://drupal.org/user/39567 * [8]
http://drupal.org/user/39593 * [9]
http://drupal.org/user/45874 * [10]
http://drupal.org/security-team

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://drupal.org/node/828986
http://drupal.org/node/828988
http://drupal.org/node/829566
http://drupal.org/project/cck
http://www.nessus.org/u?7e3054bd

Solution :

Update the affected drupal-cck package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)

Family: Fedora Local Security Checks

Nessus Plugin ID: 47211 (fedora_2010-10127.nasl)

Bugtraq ID:

CVE ID: CVE-2010-2352
CVE-2010-2353

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now