Fix critical security issues in drupal packages
Bug #431080 reported by
Scott Testerman
This bug affects 4 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
drupal5 (Debian) |
Fix Released
|
Unknown
|
|||
drupal5 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned | ||
Intrepid |
Fix Released
|
Undecided
|
Unassigned | ||
Jaunty |
Fix Released
|
Undecided
|
Unassigned | ||
Karmic |
Fix Released
|
Undecided
|
Unassigned | ||
drupal6 (Debian) |
Fix Released
|
Unknown
|
|||
drupal6 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Undecided
|
Unassigned | ||
Intrepid |
Invalid
|
Undecided
|
Unassigned | ||
Jaunty |
Fix Released
|
Undecided
|
Unassigned | ||
Karmic |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: drupal5
Full details about the security issue addressed by this bugfix are available at http://
The vulnerability is:
* Attacker can fix and reuse a victim's session ID.
visibility: | private → public |
Changed in drupal5 (Debian): | |
status: | Unknown → New |
Changed in drupal5 (Ubuntu Karmic): | |
assignee: | nobody → Artur Rona (ari-tczew) |
Changed in drupal5 (Ubuntu Karmic): | |
status: | Incomplete → In Progress |
summary: |
- Drupal 5.20 released to fix critical security vulnerability + Fix critical security vulnerability (SA-CORE-2009-008) |
Changed in drupal6 (Ubuntu Karmic): | |
assignee: | nobody → Artur Rona (ari-tczew) |
status: | New → In Progress |
Changed in drupal6 (Ubuntu Jaunty): | |
assignee: | nobody → Artur Rona (ari-tczew) |
status: | New → In Progress |
description: | updated |
tags: | added: patch |
Changed in drupal5 (Ubuntu Jaunty): | |
status: | In Progress → Triaged |
Changed in drupal6 (Ubuntu Jaunty): | |
status: | In Progress → Triaged |
Changed in drupal6 (Debian): | |
status: | Unknown → Fix Released |
Changed in drupal6 (Ubuntu Hardy): | |
status: | New → Invalid |
Changed in drupal6 (Ubuntu Intrepid): | |
status: | New → Invalid |
Changed in drupal6 (Ubuntu Karmic): | |
assignee: | Artur Rona (ari-tczew) → nobody |
status: | In Progress → New |
Changed in drupal5 (Debian): | |
importance: | Undecided → Unknown |
status: | Fix Released → Unknown |
Changed in drupal5 (Debian): | |
status: | Unknown → Fix Released |
Changed in drupal6 (Ubuntu Karmic): | |
status: | New → Fix Committed |
Changed in drupal5 (Ubuntu Jaunty): | |
status: | Triaged → In Progress |
Changed in drupal5 (Ubuntu Jaunty): | |
assignee: | Artur Rona (ari-tczew) → nobody |
status: | In Progress → New |
Changed in drupal6 (Ubuntu Jaunty): | |
status: | Triaged → In Progress |
Changed in drupal5 (Ubuntu Hardy): | |
assignee: | nobody → Artur Rona (ari-tczew) |
Changed in drupal5 (Ubuntu Intrepid): | |
assignee: | nobody → Artur Rona (ari-tczew) |
summary: |
- Fix critical security vulnerability (SA-CORE-2009-008) + Fix critical security issues in drupal packages |
Changed in drupal5 (Ubuntu Intrepid): | |
status: | Incomplete → In Progress |
Changed in drupal5 (Ubuntu Intrepid): | |
assignee: | nobody → Artur Rona (ari-tczew) |
status: | New → In Progress |
Changed in drupal5 (Ubuntu Hardy): | |
status: | Incomplete → In Progress |
Changed in drupal5 (Ubuntu Intrepid): | |
status: | In Progress → New |
assignee: | Artur Rona (ari-tczew) → nobody |
Changed in drupal5 (Ubuntu Intrepid): | |
status: | New → Confirmed |
To post a comment you must log in.
Diff attached for Hardy