Bug 19812 - drupal new security issues fixed upstream in 7.52 (CVE-2016-9449 and CVE-2016-9451)
Summary: drupal new security issues fixed upstream in 7.52 (CVE-2016-9449 and CVE-2016...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/706841/
Whiteboard: has_procedure advisory MGA5-64-OK MGA...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-11-18 13:39 CET by David Walser
Modified: 2016-12-07 13:09 CET (History)
4 users (show)

See Also:
Source RPM: drupal-7.44-1.mga5.src.rpm
CVE: CVE-2016-9449 CVE-2016-9451
Status comment:


Attachments

Comment 1 David Walser 2016-11-18 13:39:25 CET
Testing procedures:
https://bugs.mageia.org/show_bug.cgi?id=14298#c6

Whiteboard: (none) => has_procedure

Comment 2 David Walser 2016-11-18 17:21:59 CET
Debian has issued an advisory for this on November 17:
https://www.debian.org/security/2016/dsa-3718

URL: (none) => http://lwn.net/Vulnerabilities/706841/

Comment 4 David Walser 2016-11-21 21:02:50 CET
LWN references with the CVEs:
https://lwn.net/Vulnerabilities/707038/
https://lwn.net/Vulnerabilities/707041/
Dave Hodgins 2016-11-21 22:39:14 CET

CC: (none) => davidwhodgins
Whiteboard: has_procedure => has_procedure advisory

Comment 5 Lewis Smith 2016-11-27 10:06:12 CET
Testing M5 x64 real hardware.

I already have Drupal installed, using Postgres, so:
 UPDATED to: drupal-7.52-1.mga5, drupal-postgresql-7.52-1.mga5
without problems.

Played with it (http://localhost/drupal), added an Article with a picture, modified a previous one, edited a Basic Page. OK for me.

If the 32-bit tester can use MariaDB/MySQL, so much the better.

CC: (none) => lewyssmith
Whiteboard: has_procedure advisory => has_procedure advisory MGA5-64-OK

Comment 6 youpburden 2016-11-27 10:15:03 CET
Mageia5-32 on Virtualbox 5.0.8 with guest additions and real hardware (AMD free driver)

I installedd MariaDB with Drupal 7.52-1.mag5 without problem.

Then, I created some pages with texts, images, weblinks ...
Everything has been working without issues for 4 hours now.

Same results on Virutalbox and real hardware so it's ok for me.

CC: (none) => youpburden

Comment 7 youpburden 2016-12-06 16:13:34 CET
(In reply to youpburden from comment #6)
> Mageia5-32 on Virtualbox 5.0.8 with guest additions and real hardware (AMD
> free driver)
> 
> I installedd MariaDB with Drupal 7.52-1.mag5 without problem.
> 
> Then, I created some pages with texts, images, weblinks ...
> Everything has been working without issues for 4 hours now.
> 
> Same results on Virutalbox and real hardware so it's ok for me.

It's been a week now and Drupal is still working fine.

MGA5-32-OK

Whiteboard: has_procedure advisory MGA5-64-OK => has_procedure advisory MGA5-64-OK MGA5-32-OK

youpburden 2016-12-07 09:55:20 CET

Keywords: (none) => validated_update
CVE: (none) => CVE-2016-9449, CVE-2016-9450, CVE-2016-9452, CVE-2016-9451
CC: (none) => sysadmin-bugs

Comment 8 Mageia Robot 2016-12-07 12:49:45 CET
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0413.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2016-12-07 13:09:37 CET

CVE: CVE-2016-9449, CVE-2016-9450, CVE-2016-9452, CVE-2016-9451 => CVE-2016-9449 CVE-2016-9451


Note You need to log in before you can comment on or make changes to this bug.