exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

DRUPAL-SA-2007-002.txt

DRUPAL-SA-2007-002.txt
Posted Jan 7, 2007
Authored by Uwe Hermann | Site drupal.org

Drupal security advisory - The way page caching was implemented allows a denial of service attack. An attacker has to have the ability to post content on the site. He or she would then be able to poison the page cache, so that it returns cached 404 page not found errors for existing pages. If the page cache is not enabled, your site is not vulnerable. The vulnerability only affects sites running on top of MySQL.

tags | advisory, denial of service
SHA-256 | 586514a30d2638ed99461f42690efaf3b811a03e2eafffba2aa3d38eb5218f2e

DRUPAL-SA-2007-002.txt

Change Mirror Download
----------------------------------------------------------------------------
Drupal security advisory DRUPAL-SA-2007-002
----------------------------------------------------------------------------
Project: Drupal core.
Date: 2007-Jan-05.
Security risk: Less critical.
Exploitable from: Remote.
Vulnerability: Denial of service.
----------------------------------------------------------------------------

Description
-----------
The way page caching was implemented allows a denial of service attack.
An attacker has to have the ability to post content on the site. He or she
would then be able to poison the page cache, so that it returns cached 404
page not found errors for existing pages.

If the page cache is not enabled, your site is not vulnerable. The
vulnerability only affects sites running on top of MySQL.


Versions affected
-----------------
- Drupal 4.6.x versions before Drupal 4.6.11
- Drupal 4.7.x versions before Drupal 4.7.5

Solution
--------
- If you are running Drupal 4.6.x then upgrade to Drupal 4.6.11.
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
- If you are running Drupal 4.7.x then upgrade to Drupal 4.7.5.
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz

- To patch Drupal 4.6.10 use http://drupal.org/files/sa-2006-002/4.6.10.patch.
- To patch Drupal 4.7.4 use http://drupal.org/files/sa-2006-002/4.7.4.patch.

Please note that the patches only contain changes related to this advisory, and
do not fix bugs that were solved in 4.6.11 or 4.7.5.

Reported by
-----------
Drupal security team.

Contact
-------
The security contact for Drupal can be reached at security at drupal.org or
using the form at http://drupal.org/contact.


// Uwe Hermann, on behalf of the Drupal Security Team.
--
http://www.hermann-uwe.de | http://www.holsham-traders.de
http://www.crazy-hacks.org | http://www.unmaintained-free-software.org
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close