Lucid package of Drupal 6 contains critical security bugs

Bug #929510 reported by Daniel James
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
drupal6 (Ubuntu)
Triaged
Undecided
Unassigned

Bug Description

The drupal6 package for Lucid LTS has not been updated in more than a year. There is no mention of the multiple vulnerabilities disclosed in May 2011 (http://drupal.org/node/1168756) or last week (http://drupal.org/node/1425084) being patched in the Lucid package:

http://changelogs.ubuntu.com/changelogs/pool/universe/d/drupal6/drupal6_6.16-1ubuntu0.1/changelog

Please patch the drupal6 package or update it to at least Drupal 6.23 for the benefit of all the Drupal 6 web servers running on Lucid.

Thanks!

Daniel

CVE References

Revision history for this message
Steve Beattie (sbeattie) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

visibility: private → public
visibility: private → public
Changed in drupal6 (Ubuntu):
status: New → Triaged
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.