Drupal5: SA-2007-031, SA-2008-005,SA-2008-006: SQL injection and XSS

Bug #181984 reported by Emanuele Gentili
264
Affects Status Importance Assigned to Milestone
drupal (Ubuntu)
Won't Fix
Undecided
Unassigned
Feisty
Fix Released
Undecided
Unassigned
Gutsy
Won't Fix
Undecided
Unassigned
Hardy
Won't Fix
Undecided
Unassigned
drupal5 (Ubuntu)
Fix Released
Undecided
Unassigned
Feisty
Fix Released
Undecided
Unassigned
Gutsy
Fix Released
Undecided
Unassigned
Hardy
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: drupal5

drupal5 (5.2-2ubuntu2.2) gutsy-security; urgency=low

  * SECURITY UPDATE:
    Fix several security issues found in drupal 5.4.
  * Patches are taken from the drupal security announcememnts:
    - SA-2007-31: SQJ injection possible when certain contributed modules are enabled
  * References:
    - SA-2007-31: http://drupal.org/node/198162

CVE References

Revision history for this message
Emanuele Gentili (emgent) wrote :
Changed in drupal5:
status: New → Confirmed
Revision history for this message
Emanuele Gentili (emgent) wrote :

Sorry for first patch, i recreate it with dpatch system now.

Hardy not affected, affected only Guitsy and Feisty (patch attached)

Changed in drupal5:
status: Confirmed → Fix Released
Changed in drupal:
status: New → Won't Fix
status: New → Won't Fix
Changed in drupal5:
status: New → Won't Fix
Changed in drupal:
status: New → Won't Fix
Changed in drupal5:
status: New → Confirmed
Revision history for this message
Stephan Rügamer (sruegamer) wrote :

Hi Emanuele,

I checked the diff and found that the security patch from drupal is not fixed (see http://drupal.org/drupal-5.5 and http://drupal.org/node/198321)

would you fix this too and add the new security fixes SA-2008-0005 and SA-2008-0006 to the gutsy and feisty package?

SA-2008-0007 is just an advisory to disable register_globals in your local php/apache configuration ;)

Revision history for this message
Emanuele Gentili (emgent) wrote :

Thanks Stephan Hermann, this LP bug was for SA-2007-031, but tomorrow i will see && fix other bugs too.

Cheers,

Eamanuele

Revision history for this message
Emanuele Gentili (emgent) wrote :

drupal5 (5.2-2ubuntu2.2) gutsy-security; urgency=low

  * SECURITY UPDATE: (LP: 181984)
    - SA-2007-031: SQL injection posssible when certain
      contribuited modules are enabled
    - SA-2008-005: Cross site request forgery
    - SA-2008-006: Cross site scripting (UTF8)
  * References:
    - SA-2007-031: http://drupal.org/node/198162
    - SA-2008-005: http://drupal.org/node/208562
    - SA-2008-006: http://drupal.org/node/208564

 -- Emanuele Gentili <email address hidden> Tue, 15 Jan 2008 13:57:17 +0100

Revision history for this message
Emanuele Gentili (emgent) wrote :

drupal (5.1-0ubuntu2.3) feisty-security; urgency=low

  * SECURITY UPDATE: (LP: 181984)
    - SA-2007-031: SQL injection posssible when certain
      contribuited modules are enabled
    - SA-2008-005: Cross site request forgery
    - SA-2008-006: Cross site scripting (UTF8)
  * References:
    - SA-2007-031: http://drupal.org/node/198162
    - SA-2008-005: http://drupal.org/node/208562
    - SA-2008-006: http://drupal.org/node/208564

 -- Emanuele Gentili <email address hidden> Wed, 16 Jan 2008 01:29:22 +0100

Revision history for this message
Emanuele Gentili (emgent) wrote :

corrected debdiff to feisty.

Changed in drupal5:
status: Won't Fix → Confirmed
Revision history for this message
Emanuele Gentili (emgent) wrote :

Upstream re-fix SA-2007-031 patch, and I update debdiff with it.

Revision history for this message
Emanuele Gentili (emgent) wrote :

Upstream re-fix SA-2007-031 patch, and I update debdiff with it. (for feisty too)

Revision history for this message
Emanuele Gentili (emgent) wrote :

ultimate fix, now done for uploading. (gutsy)

Revision history for this message
Emanuele Gentili (emgent) wrote :

ultimate fix, now done for uploading. (feisty)

Changed in drupal5:
status: Confirmed → Fix Committed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Emanuele, I have uploaded the updated gutsy package, but the feisty debdiff does not match up with upstream. These are the changes I am seeing (from upstream SA-2008-005-5.5.patch to the 28_SA-2008-005-5.5.dpatch
< + 'callback' => 'drupal_get_form',
---
> + 'callback' => 'drupal_get_from',

In the future, when supplying debdiffs, please try to use the 'patch' program when possible rather than manually editing when at all possible, and test the program to make sure it works properly. As this was such a small change, I have edited the patch and have uploaded it. Thanks for you work on this!

Changed in drupal5:
status: Confirmed → Fix Committed
Changed in drupal5:
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
Changed in drupal:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.