it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] SA-CONTRIB-2014-056 - Commerce Moneris - Information Disclosure
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] SA-CONTRIB-2014-056 - Commerce Moneris - Information Disclosure
- Date: Wed, 21 May 2014 15:56:24 +0000 (UTC)
- List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
- List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
View online: https://drupal.org/node/2271823
* Advisory ID: DRUPAL-SA-CONTRIB-2014-056
* Project: Commerce Moneris [1] (third-party module)
* Version: 7.x
* Date: 2014-May-21
* Security risk: Critical [2]
* Exploitable from: Remote
* Vulnerability: Information Disclosure
-------- DESCRIPTION
---------------------------------------------------------
Commerce Moneris is a payment module that integrates the Moneris payment
system with Drupal Commerce [3].
The module stores credit card data in a commerce order object unnecessarily
for the purpose of passing the credit card information to the payment
gateway. The credit card information is never removed from the order object
and is later saved in the clear as serialized data in the database.
This vulnerability is mitigated by the fact that an attacker must have access
to the database or the ability to execute PHP to output the raw or
unserialized data from the commerce order.
-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------
* /A CVE identifier [4] will be requested, and added upon issuance, in
accordance with Drupal Security Team processes./
-------- VERSIONS AFFECTED
---------------------------------------------------
* Commerce Moneris 7.x-1.x versions prior to 7.x-1.4.
Drupal core is not affected. If you do not use the contributed Commerce
Moneris [5] module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
Install the latest version:
* If you use the Commerce Moneris module for Drupal 7.x, upgrade to
Commerce
Moneris 7.x-1.4 [6]
Also see the Commerce Moneris [7] project page.
-------- REPORTED BY
---------------------------------------------------------
* Ryan Szrama [8]
-------- FIXED BY
------------------------------------------------------------
* Scott Reeves [9], module co-maintainer
-------- COORDINATED BY
------------------------------------------------------
* Rick Manelius [10] of the Drupal Security Team
* Klaus Purer [11] of the Drupal Security Team
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [12].
Learn more about the Drupal Security team and their policies [13], writing
secure code for Drupal [14], and securing your site [15].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [16]
[1] http://drupal.org/project/commerce_moneris
[2] http://drupal.org/security-team/risk-levels
[3] https://drupal.org/project/commerce
[4] http://cve.mitre.org/
[5] http://drupal.org/project/commerce_moneris
[6] https://drupal.org/node/2271789
[7] http://drupal.org/project/commerce_moneris
[8] https://drupal.org/user/49344
[9] https://drupal.org/user/1167326
[10] https://drupal.org/user/680072
[11] https://drupal.org/user/262198
[12] http://drupal.org/contact
[13] http://drupal.org/security-team
[14] http://drupal.org/writing-secure-code
[15] http://drupal.org/security/secure-configuration
[16] https://twitter.com/drupalsecurity
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at http://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] SA-CONTRIB-2014-056 - Commerce Moneris - Information Disclosure, security-news, 21.05.2014
Archiv bereitgestellt durch MHonArc 2.6.19.