-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : drupal7 Version : 7.14-2+deb7u16 CVE ID : CVE-2017-6922
Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system. For Debian 7 "Wheezy", these problems have been fixed in version 7.14-2+deb7u16. We recommend that you upgrade your drupal7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEjtbD+LrJ23/BMKhw+COicpiDyXwFAllT0DYACgkQ+COicpiD yXyNYw//TMhWtAnT9XQVOSNgXIEM/0Gy4CNe6YEFuasrUE7P1G79bKdeX2OT18ur IcaGWbsYwqy9eZLCUmYCtlmkvnvhzjK9McA/dMTnGlLUzRbKyum1fS4pJTlkjsBk yvC5NQ7Yj7GB8nPH0/4SzqclrrDV2wth0luYM0oSU4uF0bB57N7h/fXdNuX6uogH y1LL9O5RqySjeSgSHHwxDiqp6A+eNZU8gTr6eX/zRaMoBrzX3pO1DUYX0gM0Sa9K HoalLIlARWbDiJxciEaiLma+uIaLF34D1h5zisH+URU3HqUz34xoe91gaN2EqC5O A6q22WtIzmszb8jefUd1fs3i8CNdxCOwFO0c2gOAdGc5T7ExZoILwbU+OhZ53qNZ 1kHLQZHnFYgNlaw1c8JbEKaOU/xqNLSwMd+l6fvBnsuSEnauqCg0uwsRtHhROjm+ aiORwOcsUj28XUPOWoQywzvJX6OuboSrEYBifaNndS8Wk4uxU7xkVRy4R6y3l0Kr 5sJxcg7ZfnQ5aHc8qbvxbB7/ZugVHhFSvOHJ8q7+jblND/EIKIVT7Q1bcoXaArY7 0d/sLvrtzNcummWQgduVXpbqEPZNpVLLkAmM5GgsFnLyKRbXx1V4dm3aOVkfVyGp +d/dvCIbi/2gzImMNDGqE3KsuTuZEBJUA/uvQwP8YrGPHnKcl8A= =3ryC -----END PGP SIGNATURE-----