drupal6
- Author: Miklos Vajna
- Vulnerable: 6.10-1
- Unaffected: 6.11-1anacreon1
See FSA594.
- Bug Tracker URL: http://bugs.frugalware.org/task/3760
CVEs:
- No CVE, see http://drupal.org/node/449078.
This is a list of security announcments that have been released for the current stable version of Frugalware
See FSA594.
Some vulnerabilities, security issues, and a weakness have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, conduct cross-site scripting and cross-site request forgery attacks, and potentially compromise a user’s system.
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a user’s system.
Some vulnerabilities have been reported in OpenSSL, which can be exploited by malicious people to bypass certain security restrictions or cause a DoS (Denial of Service).
Some vulnerabilities have been reported in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks or compromise a vulnerable system.
A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the setup script not properly sanitising configuration parameters. This can be exploited to inject arbitrary PHP code into the phpMyAdmin configuration file. This is related to vulnerability #2 in: FSA591 NOTE: Successful exploitation requires that installation best-practices have not been followed and the setup scripts have not been deleted after a successful installation.
Some vulnerabilities have been reported in udev, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges.
Some vulnerabilities have been reported in Wireshark, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user’s system.
A security issue has been reported in the CCK Field Privacy module for Drupal, which can be exploited by malicious people to bypass certain security restrictions. The security issue is caused due to the application not properly restricting access to certain administrative pages and can be exploited to e.g. change permissions on fields.
Some vulnerabilities have been discovered in GNU Enscript, which can be exploited by malicious people to compromise a vulnerable system.