[Full-disclosure] [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue

2007-01-29 Thread Uwe Hermann
at security at drupal.org or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal Security Team. -- http://www.hermann-uwe.de | http://www.holsham-traders.de http://www.crazy-hacks.org | http://www.unmaintained-free-software.org signature.asc Description

[Full-disclosure] [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue

2007-01-05 Thread Uwe Hermann
bugs that were solved in 4.6.11 or 4.7.5. Reported by --- Anonymous via JPCERT. Contact --- The security contact for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal Security Team. -- http

[Full-disclosure] [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue

2007-01-05 Thread Uwe Hermann
contain changes related to this advisory, and do not fix bugs that were solved in 4.6.11 or 4.7.5. Reported by --- Drupal security team. Contact --- The security contact for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact. // Uwe

[Full-disclosure] [DRUPAL-SA-2006-025] Drupal 4.6.10 / 4.7.4 fixes CRF issue

2006-10-19 Thread Uwe Hermann
://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http://www.unmaintained-free-software.org signature.asc Description: Digital

[Full-disclosure] [DRUPAL-SA-2006-024] Drupal 4.6.10 / 4.7.4 fixes multiple XSS issues

2006-10-19 Thread Uwe Hermann
vulnerability was reported by Jim Phlew. - The other vulnerabilities were found by members of the Drupal security team. Contact --- The security contact for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal

[Full-disclosure] [DRUPAL-SA-2006-026] Drupal 4.6.10 / 4.7.4 fixes HTML attribute injection issue

2006-10-19 Thread Uwe Hermann
that were solved in 4.6.10 or 4.7.4. Reported by --- Frederic Marand. Contact --- The security contact for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http

[Full-disclosure] [DRUPAL-SA-2006-011] Drupal 4.7.3 / 4.6.9 fixes XSS issue

2006-08-03 Thread Uwe Hermann
Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http://www.unmaintained-free-software.org signature.asc Description: Digital signature

[Full-disclosure] [DRUPAL-SA-2006-005] Drupal 4.6.7 / 4.7.1 fixes SQL injection issue

2006-06-02 Thread Uwe Hermann
://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http

[Full-disclosure] [DRUPAL-SA-2006-006] Drupal 4.6.7 / 4.7.1 fixes arbitrary file execution issue

2006-06-02 Thread Uwe Hermann
contact for Drupal can be reached at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. More information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann

[Full-disclosure] [DRUPAL-SA-2006-007] Drupal 4.6.8 / 4.7.2 fixes arbitrary file execution issue

2006-06-02 Thread Uwe Hermann
our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http://www.unmaintained-free-software.org

[Full-disclosure] [DRUPAL-SA-2006-001] Drupal 4.6.6 / 4.5.8 fixes access control issue

2006-03-13 Thread Uwe Hermann
--- The security contact for Drupal can be reached at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. More information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal

[Full-disclosure] [DRUPAL-SA-2006-002] Drupal 4.6.6 / 4.5.8 fixes XSS issue

2006-03-13 Thread Uwe Hermann
/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http://www.unmaintained-free-software.org signature.asc Description: Digital signature

[Full-disclosure] [DRUPAL-SA-2006-003] Drupal 4.6.6 / 4.5.8 fixes session fixation issue

2006-03-13 Thread Uwe Hermann
Contact --- The security contact for Drupal can be reached at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. More information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf

[Full-disclosure] [DRUPAL-SA-2006-004] Drupal 4.6.6 / 4.5.8 fixes mail header injection issue

2006-03-13 Thread Uwe Hermann
is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann http://www.hermann-uwe.de http://www.it-services-uh.de | http://www.crazy-hacks.org http://www.holsham-traders.de | http

[Full-disclosure] [DRUPAL-SA-2005-007] Drupal 4.6.4 / 4.5.6 fixes XSS issue

2005-12-01 Thread Uwe Hermann
for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact. More information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann [EMAIL

[Full-disclosure] [DRUPAL-SA-2005-008] Drupal 4.6.4 / 4.5.6 fixes XSS and HTTP header injection issue

2005-12-01 Thread Uwe Hermann
information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann [EMAIL PROTECTED] http://www.hermann-uwe.de | http://www.crazy-hacks.org http://www.it-services

[Full-disclosure] [DRUPAL-SA-2005-009] Drupal 4.6.4 / 4.5.6 fixes minor access control issue

2005-12-01 Thread Uwe Hermann
contact for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact. More information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe

[Full-disclosure] [DRUPAL-SA-2005-004] Drupal 4.6.3 / 4.5.5 fixes critical XML-RPC issue

2005-08-14 Thread Uwe Hermann
at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann [EMAIL PROTECTED] http://www.hermann-uwe.de | http://www.crazy-hacks.org http://www.it-services-uh.de | http://www.phpmeat.org http

[Full-disclosure] [DRUPAL-SA-2005-002] Drupal 4.6.2 / 4.5.4 fixes input validation issue

2005-06-29 Thread Uwe Hermann
. - If you are running Drupal 4.5.x, then upgrade to Drupal 4.5.4. - If you are running Drupal 4.6.x, then upgrade to Drupal 4.6.2. Contact --- The security contact for Drupal can be reached at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal

[Full-disclosure] [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue

2005-06-29 Thread Uwe Hermann
at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. // Uwe Hermann, on behalf of the Drupal Security Team. -- Uwe Hermann [EMAIL PROTECTED] http://www.hermann-uwe.de | http://www.crazy-hacks.org http://www.it-services-uh.de | http://www.phpmeat.org http

[Full-disclosure] [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue

2005-06-03 Thread Uwe Hermann
registrations option to Only site administrators can create new user accounts. Contact --- The security contact for Drupal can be reached at [EMAIL PROTECTED] or using the form at http://drupal.org/contact. // Uwe Herman, on behalf of the Drupal Security Team. -- Uwe Hermann [EMAIL