Bug#896701: drupal7: CVE-2018-7602: SA-CORE-2018-004

2018-04-23 Thread Salvatore Bonaccorso
Hi,

On Mon, Apr 23, 2018 at 02:04:33PM -0500, Gunnar Wolf wrote:
> Salvatore Bonaccorso dijo [Mon, Apr 23, 2018 at 08:53:38PM +0200]:
> > The following vulnerability was published for drupal7.
> > 
> > CVE-2018-7602[0]:
> > SA-CORE-2018-004
> > 
> > If you fix the vulnerability please also make sure to include the
> > CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> > 
> > For further information see:
> > 
> > [0] https://security-tracker.debian.org/tracker/CVE-2018-7602
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7602
> > [1] https://www.drupal.org/psa-2018-003
> 
> Rather than published, they were forewarned. They will be published
> two days from now (when I expect to patch right away!)

Yes that was just a poorly worded bugreport of mine. Its just a
prenotification yet, and the known CVE id for it.

Regards,
Salvatore



Bug#896701: drupal7: CVE-2018-7602: SA-CORE-2018-004

2018-04-23 Thread Gunnar Wolf
Salvatore Bonaccorso dijo [Mon, Apr 23, 2018 at 08:53:38PM +0200]:
> The following vulnerability was published for drupal7.
> 
> CVE-2018-7602[0]:
> SA-CORE-2018-004
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> For further information see:
> 
> [0] https://security-tracker.debian.org/tracker/CVE-2018-7602
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7602
> [1] https://www.drupal.org/psa-2018-003

Rather than published, they were forewarned. They will be published
two days from now (when I expect to patch right away!)

Thanks,



Bug#896701: drupal7: CVE-2018-7602: SA-CORE-2018-004

2018-04-23 Thread Salvatore Bonaccorso
Source: drupal7
Version: 7.32-1
Severity: grave
Tags: security upstream

Hi,

The following vulnerability was published for drupal7.

CVE-2018-7602[0]:
SA-CORE-2018-004

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-7602
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7602
[1] https://www.drupal.org/psa-2018-003

Regards,
Salvatore