Bug 16997 - drupal new security issue fixed upstream in 7.41 (CVE-2015-7943)
Summary: drupal new security issue fixed upstream in 7.41 (CVE-2015-7943)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/662052/
Whiteboard: has_procedure advisory MGA5-64-OK
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-10-22 19:21 CEST by David Walser
Modified: 2015-11-04 19:03 CET (History)
3 users (show)

See Also:
Source RPM: drupal-7.39-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-10-22 19:21:09 CEST
Upstream has issued an advisory on October 21:
https://www.drupal.org/SA-CORE-2015-004

A CVE has been requested:
http://openwall.com/lists/oss-security/2015/10/21/6

Updated packages uploaded for Mageia 5 and Cauldron.

Advisory to come later.

References:
https://www.drupal.org/SA-CORE-2015-004
https://www.drupal.org/drupal-7.40
https://www.drupal.org/drupal-7.40-release-notes
https://www.drupal.org/drupal-7.41
https://www.drupal.org/drupal-7.41-release-notes
========================

Updated packages in core/updates_testing:
========================
drupal-7.41-1.mga5
drupal-mysql-7.41-1.mga5
drupal-postgresql-7.41-1.mga5
drupal-sqlite-7.41-1.mga5

from drupal-7.41-1.mga5.src.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 David Walser 2015-10-22 19:21:21 CEST
Testing procedures:
https://bugs.mageia.org/show_bug.cgi?id=14298#c6

Whiteboard: (none) => has_procedure

Comment 2 David Walser 2015-10-23 17:21:32 CEST
CVE-2015-7943 assigned:
http://openwall.com/lists/oss-security/2015/10/23/6

Advisory:
========================

Updated drupal packages fix security vulnerability:

The Overlay module in Drupal core displays administrative pages as a layer
over the current page (using JavaScript), rather than replacing the page in
the browser window. The Overlay module does not sufficiently validate URLs
prior to displaying their contents, leading to an open redirect vulnerability
(CVE-2015-7943).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7943
https://www.drupal.org/SA-CORE-2015-004
https://www.drupal.org/drupal-7.40
https://www.drupal.org/drupal-7.40-release-notes
https://www.drupal.org/drupal-7.41
https://www.drupal.org/drupal-7.41-release-notes
http://openwall.com/lists/oss-security/2015/10/23/6

Summary: drupal new security issues fixed upstream in 7.41 => drupal new security issue fixed upstream in 7.41 (CVE-2015-7943)

Dave Hodgins 2015-10-25 23:34:59 CET

CC: (none) => davidwhodgins
Whiteboard: has_procedure => has_procedure advisory

David Walser 2015-10-26 20:58:21 CET

URL: (none) => http://lwn.net/Vulnerabilities/662052/

Comment 3 Lewis Smith 2015-10-27 14:49:13 CET
Testing M5 x64 using PostgreSQL.

Updated from: drupal-7.39-1.mga5   drupal-postgresql-7.39-1.mga5
to: drupal-7.41-1.mga5   drupal-postgresql-7.41-1.mga5

Played with the result, edited a page, added a user. All seems OK within my limited knowledge of how to drive this thing. Update deemed OK.

It would be nice if a 32-bit tester could use a different database, to try two variables at once.

CC: (none) => lewyssmith
Whiteboard: has_procedure advisory => has_procedure advisory MGA5-64-OK

Comment 4 claire robinson 2015-11-02 13:14:26 CET
Potential issue: Files (.php, .txt etc.) aswell as directories under /etc/drupal/sites are executable with 755 apache:apache permissions. Previous version is the same so it may always have been this way.

Other than the above, installed and tested ok mga5 32 mysql. Created an article with an image . Adding feedback for now.

Whiteboard: has_procedure advisory MGA5-64-OK => has_procedure advisory MGA5-64-OK feedback

Comment 5 David Walser 2015-11-02 21:55:42 CET
Nice catch, that's definitely wrong.  An %attr with 0755 was on the line for /etc/drupal/sites, but not marked as %dir.  The 0755 should be unnecessary, so I deleted it.

drupal-7.41-1.1.mga5 submitted.

Whiteboard: has_procedure advisory MGA5-64-OK feedback => has_procedure MGA5-64-OK

Comment 6 claire robinson 2015-11-03 19:28:54 CET
Retested x86_64, confirmed the fix. All seems ok.

Validating drupal-7.41-1.1.mga5.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 7 David Walser 2015-11-03 19:38:30 CET
Advisory updated in SVN.

Whiteboard: has_procedure MGA5-64-OK => has_procedure advisory MGA5-64-OK

Comment 8 Mageia Robot 2015-11-04 19:03:48 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0425.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.