Ads

Drupal 4.6.6 / 4.5.8 fixes access control issue PDF Print E-mail
Wednesday, 15 March 2006
----------------------------------------------------------------------------
Drupal security advisory DRUPAL-SA-2006-001
----------------------------------------------------------------------------
Advisory ID: DRUPAL-SA-2006-001
Project: Drupal core
Date: 2006-03-13
Security risk: less critical
Impact: security bypass
Where: from remote
Vulnerability: bypass access control
----------------------------------------------------------------------------

Description
-----------
If you use menu.module to create a menu item, the page you point to will be
accessible to all, even if it is an admin page.

Versions affected
-----------------
All Drupal versions before 4.6.6.

Solution
--------
If you are running Drupal 4.5.x then upgrade to Drupal 4.5.8.
If you are running Drupal 4.6.x then upgrade to Drupal 4.6.6.

Contact
-------
The security contact for Drupal can be reached at This email address is being protected from spam bots, you need Javascript enabled to view it
or using the form at http://drupal.org/contact.
More information is available from http://drupal.org/security or from
our security RSS feed http://drupal.org/security/rss.xml.


// Uwe Hermann, on behalf of the Drupal Security Team.
-- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http://www.unmaintained-free-software.org
 
< Prev   Next >