Bug 988896 - (CVE-2016-6211) VUL-0: CVE-2016-6211,CVE-2016-6212: drupal7, drupal8: several issues fixed in 7.44
(CVE-2016-6211)
VUL-0: CVE-2016-6211,CVE-2016-6212: drupal7, drupal8: several issues fixed in...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software
unspecified
Other Other
: P5 - None : Normal (vote)
: ---
Assigned To: Eric Schirra
E-mail List
https://smash.suse.de/issue/170922/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-07-14 08:27 UTC by Andreas Stieger
Modified: 2016-07-14 15:25 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-07-14 08:27:43 UTC
Courtesy bug from the SUSE security team for
server:php:applications/drupal7
server:php:applications/drupal8



http://seclists.org/oss-sec/2016/q3/57


    https://www.drupal.org/SA-CORE-2016-002

    Saving user accounts can sometimes grant the user all roles (User
    module - Drupal 7 - Moderately Critical)

    A vulnerability exists in the User module, where if some specific
    contributed or custom code triggers a rebuild of the user profile
    form, a registered user can be granted all user roles on the site.
    This would typically result in the user gaining administrative access.


Use CVE-2016-6211.


    https://www.drupal.org/SA-CORE-2016-002
    https://www.drupal.org/node/2749333

    Views can allow unauthorized users to see Statistics information
    (Views module - Drupal 8 - Less Critical)

    An access bypass vulnerability exists in the Views module, where users
    without the "View content count" permission can see the number of hits
    collected by the Statistics module for results in the view.

    The same vulnerability exists in the Drupal 7 Views module (see
    SA-CONTRIB-2016-036).


Use CVE-2016-6212 for both the issue in Drupal Core and the issue
in the Drupal 7 Views module.



References:
https://bugzilla.redhat.com/show_bug.cgi?id=1351214
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6211
http://seclists.org/oss-sec/2016/q3/57
Comment 1 Eric Schirra 2016-07-14 15:25:34 UTC
Is fixed now.
Update to 7.50