[Security-news] SA-CONTRIB-2010-070 - Multiple vulnerabilities in multiple contributed modules
security-news at drupal.org
security-news at drupal.org
Wed Jun 23 20:53:43 UTC 2010
* Advisory ID: DRUPAL-SA-CONTRIB-2010-070
* Projects: Multiple third party modules - Easy Translator, Block Queue,
Multiple Image Upload (Imagex)
* Version: 5.x, 6.x
* Date: 2010-06-23
* Security risks: Critical
* Exploitable from: Remote
* Vulnerability: Multiple (SQL Injection, CSRF, Access bypass)
-------- VERSIONS AFFECTED AND PROPOSED SOLUTIONS
----------------------------
Easy Translator [1] for Drupal 6.x
The module is vulnerable to SQL injections. *Solution:* Disable the
module. There is no safe version of the module to use.
Block Queue [2] for Drupal 6.x
The Block Queue module allows users to create "queues" of blocks much
like NodeQueue allows to create queues for nodes. The module is
vulnerable to Cross-Site Request Forgeries as it allows a non-admin user
to trick an admin into removing blocks from queues by directing him/her
to a url via a link or image. *Solution:* Disable the module. There is no
safe version of the module to use.
Multiple Image Upload (Imagex) [3] for Drupal 5.x and 6.x
The Multiple Image Upload module enables images to be "drag 'n' dropped"
uploaded into Drupal. The module is vulnerable to access bypass.
*Solution:* Disable the module. There is no safe version of the module to
use. All releases of the module were marked unsupported earlier.
Drupal core is not affected. If you do not use any of the module releases
above there is nothing you need to do.
-------- ONGOING MAINTENANCE OF THESE MODULES
--------------------------------
If you are interested in taking over maintenance of a module, or branch of a
module, that is no longer supported, and are capable of fixing security
vulnerabilities, you may apply to do so using the abandoned project takeover
process [4].
-------- REPORTED BY
---------------------------------------------------------
* Easy Translator issue reported by Jakub Suchy [5] of the Drupal Security
Team
* Blockqueue issue reported by mr.baileys [6] of the Drupal Security Team
* Multiple Image Upload (Imagex) issue reported by Greg Knaddison [7] of the
Drupal Security Team
-------- CONTACT
-------------------------------------------------------------
The security team for Drupal [8] can be reached at security at drupal.org or
via the form at http://drupal.org/contact.
Read more about the Security Team and Security Advisories at
http://drupal.org/security.
[1] http://drupal.org/project/vitzo_easy_translator
[2] http://drupal.org/project/blockqueue
[3] http://drupal.org/project/imagex
[4] http://drupal.org/node/251466
[5] http://drupal.org/user/31977
[6] http://drupal.org/user/383424
[7] http://drupal.org/user/36762
[8] http://drupal.org/security-team
More information about the Security-news
mailing list