Vulnerability Bulletins

DSA-2851 drupal6 - impersonation

   
Affected software Debian
 
Christian Mainka and Vladislav Mladenov reported a vulnerability in theOpenID module of Drupal, a fully-featured content management framework.A malicious user could exploit this flaw to log in as other users on thesite, including administrators, and hijack their accounts.

More info:

http://www.debian.org/security/2014/dsa-2851