Drupal Drush Debian Packaging Module Local Information Disclosure Vulnerability
BID:57643
Info
Drupal Drush Debian Packaging Module Local Information Disclosure Vulnerability
| Bugtraq ID: | 57643 |
| Class: | Design Error |
| CVE: |
CVE-2013-0260 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 30 2013 12:00AM |
| Updated: | Mar 29 2013 12:17PM |
| Credit: | jiri-catalyst |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Drush Debian Packaging Module Local Information Disclosure Vulnerability
The Drush Debian Packaging module for Drupal is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
The Drush Debian Packaging module for Drupal is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Exploit / POC
Drupal Drush Debian Packaging Module Local Information Disclosure Vulnerability
An attacker requires local interactive access to the affected application to exploit this issue.
An attacker requires local interactive access to the affected application to exploit this issue.
Solution / Fix
Drupal Drush Debian Packaging Module Local Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Drupal Drush Debian Packaging Module Local Information Disclosure Vulnerability
References:
References:
- Drupal Homepage (Drupal)