drupal7 packaged version 7.12 on Ubuntu warns of security upgrade

Bug #1206907 reported by Jan Groenewald
264
This bug affects 3 people
Affects Status Importance Assigned to Milestone
drupal7 (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

When installing stock drupal7 on precise, it says:

    There is a security update available for your version of Drupal. To ensure the security of your server, you should update immediately! See the available updates page for more information and to install your missing updates.
    One or more problems were detected with your Drupal installation. Check the status report for more information.

it seems drupal 7.22 is available, clicking through to upgrades, says
Automatic updating of Drupal core is not supported. See the upgrade guide for information on how to update Drupal core manually.

I guess a packaged version is not supposed to change /usr/share/druapl7 anyway, nor am I sure whether these count as ubuntu security upgrades or whether the package will be reliable if updated as often as upstream. Thought I'd report anyway -- this is strange behaviour for an ubuntu package.

Andreas Moog (ampelbein)
information type: Public → Public Security
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in drupal7 (Ubuntu):
status: New → Incomplete
Revision history for this message
Seth Arnold (seth-arnold) wrote :

There are a variety of security issues known to affect our drupal7 packages: http://people.canonical.com/~ubuntu-security/cve/pkg/drupal7.html

Thanks

Revision history for this message
Jan Groenewald (jan-aims) wrote :

I am not able to produce a debdiff; not enough experience.
Note

0 root@rackspace:/etc/drupal/7#apt-cache show drupal7|grep Maint
Maintainer: Ubuntu Developers <email address hidden>
Original-Maintainer: Luigi Gangitano <email address hidden>

Note the latest version is in saucy:
http://packages.ubuntu.com/search?keywords=drupal7&searchon=names&suite=all&section=all

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for drupal7 (Ubuntu) because there has been no activity for 60 days.]

Changed in drupal7 (Ubuntu):
status: Incomplete → Expired
Changed in drupal7 (Ubuntu):
status: Expired → Confirmed
Revision history for this message
Christoph_vW (christoph-apiviewer) wrote :
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.