Boletines de Vulnerabilidades

DSA-2851 drupal6 - impersonation


Información sobre el sistema

   
Software afectado Debian

Descripción

Christian Mainka and Vladislav Mladenov reported a vulnerability in theOpenID module of Drupal, a fully-featured content management framework.A malicious user could exploit this flaw to log in as other users on thesite, including administrators, and hijack their accounts.

More info:

http://www.debian.org/security/2014/dsa-2851

Identificadores estándar

Propiedad Valor
CVE CVE-2014-1475 and DSA-2851.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-02-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT