Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-031 - Menu Block - Cross Site Scripting (XSS)

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-031 - Menu Block - Cross Site Scripting (XSS)


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-031 - Menu Block - Cross Site Scripting (XSS)
  • Date: Wed, 24 Mar 2010 23:58:06 +0000 (UTC)
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>

* Advisory ID: DRUPAL-SA-CONTRIB-2010-031
* Project: Menu Block (third-party module)
* Versions: 6.x-2.x, 5.x-2.x, 5.x-1.x
* Date: 2010-March-24
* Security risk: Less Critical
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting

-------- DESCRIPTION
---------------------------------------------------------

The Menu Block module generates full or partial menu trees that are presented
in configurable blocks. When partial menu trees are displayed, the block
title uses the text from the partial menu tree's parent menu item. However,
that text is not properly sanitized, leading to a Cross Site Scripting (XSS)
vulnerability. XSS vulnerabilities may expose site administrative accounts
which could lead to a variety of additional compromises. This vulnerability
is mitigated by the fact that an attacker must have the "administer menu"
permission which should generally only be granted to trusted roles.
-------- VERSIONS AFFECTED
---------------------------------------------------

* Menu Block module for Drupal 6.x version prior to 6.x-2.3.
* Menu Block module for Drupal 5.x versions prior to 5.x-2.1 or 5.x-1.1.

Drupal core is not affected. If you do not use the contributed Menu Block
module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------

Install the latest version.
* If you use the Menu Block module for Drupal 6.x-2.x upgrade to Menu Block
6.x-2.3 [1]
* If you use the Menu Block module for Drupal 5.x-2.x upgrade to Menu Block
5.x-2.1 [2]
* If you use the Menu Block module for Drupal 5.x-1.x upgrade to Menu Block
5.x-1.1 [3]

-------- REPORTED BY
---------------------------------------------------------

* imonemus [4]

-------- FIXED BY
------------------------------------------------------------

* JohnAlbin [5], the module maintainer.

-------- CONTACT
-------------------------------------------------------------

The security team for Drupal can be reached at security at drupal.org or via
the form at http://drupal.org/contact.

[1] http://drupal.org/node/752248
[2] http://drupal.org/node/752246
[3] http://drupal.org/node/752244
[4] http://drupal.org/user/682372
[5] http://drupal.org/user/32095

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news



  • [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-031 - Menu Block - Cross Site Scripting (XSS), security-news, 25.03.2010

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang