Git-Url: http://git.frugalware.org/gitweb/gitweb.cgi?p=homepage-ng.git;a=commitdiff;h=9edeba1cb91ac5cba2dceee51d960b33d6761340
commit 9edeba1cb91ac5cba2dceee51d960b33d6761340 Author: Miklos Vajna <vmik...@frugalware.org> Date: Wed Jul 27 00:55:23 2011 +0200 FSA730-drupal6-devel diff --git a/frugalware/xml/security.xml b/frugalware/xml/security.xml index c8ed8b2..f034719 100644 --- a/frugalware/xml/security.xml +++ b/frugalware/xml/security.xml @@ -26,6 +26,18 @@ <fsas> <fsa> + <id>730</id> + <date>2011-07-27</date> + <author>Miklos Vajna</author> + <package>drupal6-devel</package> + <vulnerable>6.x_1.23-1</vulnerable> + <unaffected>6.x_1.25-1nexon1</unaffected> + <bts>http://bugs.frugalware.org/task/4531</bts> + <cve>No CVE references, see http://drupal.org/node/1224852</cve> + <desc>A vulnerability has been reported in the Devel module for Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks. + The application allows users to perform certain actions in the Switch User block via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain unspecified actions by tricking a logged in user into visiting a malicious web site.</desc> + </fsa> + <fsa> <id>729</id> <date>2011-07-07</date> <author>Miklos Vajna</author> _______________________________________________ Frugalware-git mailing list Frugalware-git@frugalware.org http://frugalware.org/mailman/listinfo/frugalware-git