Drupal View User Profile Authorization Bypass Vulnerability
BID:15674
Info
Drupal View User Profile Authorization Bypass Vulnerability
| Bugtraq ID: | 15674 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-3974 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2005 12:00AM |
| Updated: | Feb 07 2006 08:54PM |
| Credit: | Andrew Widdowson is credited with the discovery of this vulnerability. |
| Vulnerable: |
Drupal Drupal 4.6.3 Drupal Drupal 4.6.2 Drupal Drupal 4.6.1 Drupal Drupal 4.6 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Drupal Drupal 4.6.4 |
Discussion
Drupal View User Profile Authorization Bypass Vulnerability
Drupal is prone to an authorization-bypass vulnerability. This issue is due to an unspecified error when the application is running under PHP5.
An attacker can exploit this vulnerability to bypass permissions and gain access to user profiles; this may result in information disclosure.
Drupal is prone to an authorization-bypass vulnerability. This issue is due to an unspecified error when the application is running under PHP5.
An attacker can exploit this vulnerability to bypass permissions and gain access to user profiles; this may result in information disclosure.
Exploit / POC
Drupal View User Profile Authorization Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Drupal View User Profile Authorization Bypass Vulnerability
Solution:
Debian Linux has released security advisory DSA 958-1 addressing this and other issues. Please see the referenced advisory for further information.
The vendor has released an update addressing this issue:
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Solution:
Debian Linux has released security advisory DSA 958-1 addressing this and other issues. Please see the referenced advisory for further information.
The vendor has released an update addressing this issue:
Drupal Drupal 4.6
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.1
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.2
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.3
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
References
Drupal View User Profile Authorization Bypass Vulnerability
References:
References: