Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] SA-CONTRIB-2011-024 - Spam - Cross Site Request Forgery (CSFR)

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] SA-CONTRIB-2011-024 - Spam - Cross Site Request Forgery (CSFR)


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] SA-CONTRIB-2011-024 - Spam - Cross Site Request Forgery (CSFR)
  • Date: Thu, 9 Jun 2011 02:02:43 +0000 (UTC)
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>

* Advisory ID: DRUPAL-SA-CONTRIB-2011-024
* Project: Spam [1] (third-party module)
* Version: 6.x
* Date: 2011-June-08
* Security risk: Moderately critical [2]
* Exploitable from: Remote
* Vulnerability: Cross Site Request Forgery

-------- DESCRIPTION
---------------------------------------------------------

The Spam module provides numerous tools to auto-detect and deal with spam
content that is posted to your site, without having to rely on third-party
services.

The Spam module provides a trainable Bayesian filter, automatic learning of
spammer URLs, flagging of content with an excessive number of links, the
ability to create custom filters, and more.

The module does not properly protect "mark as spam" links against Cross-site
Request Forgeries (CSRF), allowing a malicious user to trick an authorized
user into marking content as spam. Wikipedia has more information about
cross-site request forgery [3].

-------- VERSIONS AFFECTED
---------------------------------------------------

* Spam module 6.x-1.x versions prior to 6.x-1.1

Drupal core is not affected. If you do not use the contributed Spam [4]
module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

* If you use the spam module for Drupal 6.x upgrade to 6.x-1.1 [5]

See also the Spam [6] project page.

-------- REPORTED BY
---------------------------------------------------------

* Gerhard Killesreiter [7] of the Drupal Security Team

-------- FIXED BY
------------------------------------------------------------

* Gerhard Killesreiter [8] a module maintainer

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [9].

Learn more about the Drupal Security team and their policies [10], writing
secure code for Drupal [11], and securing your site [12].


[1] http://drupal.org/project/spam
[2] http://drupal.org/security-team/risk-levels
[3] http://en.wikipedia.org/wiki/Cross-site_scripting
[4] http://drupal.org/project/spam
[5] http://drupal.org/node/1183114
[6] http://drupal.org/project/spam
[7] http://drupal.org/user/227
[8] http://drupal.org/user/227
[9] http://drupal.org/contact
[10] http://drupal.org/security-team
[11] http://drupal.org/writing-secure-code
[12] http://drupal.org/security/secure-configuration

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news



  • [IT-SecNots] [Security-news] SA-CONTRIB-2011-024 - Spam - Cross Site Request Forgery (CSFR), security-news, 09.06.2011

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang