Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] SA-CONTRIB-2011-021 - Webform - Multiple Vulnerabilities

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] SA-CONTRIB-2011-021 - Webform - Multiple Vulnerabilities


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] SA-CONTRIB-2011-021 - Webform - Multiple Vulnerabilities
  • Date: Wed, 18 May 2011 23:52:05 +0000 (UTC)
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>

* Advisory ID: DRUPAL-SA-CONTRIB-2010-021
* Project: Webform [1] (third-party module)
* Version: 6.x, 7.x
* Date: 2010-May-18
* Security risk: Moderately critical [2]
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting, Multiple vulnerabilities

-------- DESCRIPTION
---------------------------------------------------------

Webform module enables you to create custom webform or survey nodes. These
nodes typically may be created either by editorial teams or administrators.
Webform does not sufficiently check directory access when a user configures
an upload field. This may allow a user to upload malicious files to the
server in unsafe locations but is mitigated by the fact that a properly
configured will use directory access control to limit those locations.
Webform also does not properly sanitize some user-submitted information
leading to XSS vulnerabilities.

Most of these vulnerabilities are mitigated by the fact that an attacker must
have a role with the permission "create webform content" or "administer
nodes". The user must be able to create a webform node (or another node type
that has been Webform-enabled) in order leverage these exploits. One
vulnerability requires that a malicious user has a role that can submit a
webform that accepts file uploads which is a more common scenario.

-------- VERSIONS AFFECTED
---------------------------------------------------

* 6.x-2.10
* 6.x-3.9
* 7.x-3.9

Drupal core is not affected. If you do not use the contributed Webform [3]
module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

* If you use the 2.10 or 3.9 versions of the module for Drupal 6.x upgrade
to Webform 6.x-3.10 [4] (security fix only) or Webform 6.x-3.11 [5]
(security fix and latest fixes/features),
* If you use the 3.9 versions of the module for Drupal 7.x upgrade to
Webform 7.x-3.10 [6] (security fix only) or Webform 7.x-3.11 [7] (security
fix and latest fixes/features),

See also the Webform [8] project page.

-------- REPORTED BY
---------------------------------------------------------

* Justin Klein Keane [9] of the Drupal Security Team

-------- FIXED BY
------------------------------------------------------------

* Nathan Haug [10] the module maintainer
* Justin Klein Keane [11] of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [12].

Learn more about the Drupal Security team and their policies [13], writing
secure code for Drupal [14], and securing your site [15].


[1] http://drupal.org/project/webform
[2] http://drupal.org/security-team/risk-levels
[3] http://drupal.org/project/webform
[4] http://drupal.org/node/1161880
[5] http://drupal.org/node/1161904
[6] http://drupal.org/node/1161882
[7] http://drupal.org/node/1161906
[8] http://drupal.org/project/webform
[9] http://drupal.org/user/302225
[10] http://drupal.org/user/35821
[11] http://drupal.org/user/302225
[12] http://drupal.org/contact
[13] http://drupal.org/security-team
[14] http://drupal.org/writing-secure-code
[15] http://drupal.org/security/secure-configuration

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news



  • [IT-SecNots] [Security-news] SA-CONTRIB-2011-021 - Webform - Multiple Vulnerabilities, security-news, 19.05.2011

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang