Re: www/drupal4 and www/drupal5: Multiple security vulnerabilities



Linh Pham wrote:
The Drupal project announced several security vulnerabilities for the
4.7.x and 5.x releases of the Drupal package. These effect two current
ports: www/drupal4 and www/drupal5.

The following are the security advisories that were posted:

4.7.x:
* DRUPAL-SA-2007-024: http://drupal.org/node/184315
* DRUPAL-SA-2007-026: http://drupal.org/node/184320
* DRUPAL-SA-2007-030: http://drupal.org/node/184354

5.x:
* DRUPAL-SA-2007-024: http://drupal.org/node/184315
* DRUPAL-SA-2007-025: http://drupal.org/node/184316
* DRUPAL-SA-2007-026: http://drupal.org/node/184320
* DRUPAL-SA-2007-029: http://drupal.org/node/184348
* DRUPAL-SA-2007-030: http://drupal.org/node/184354

While patches are available for 4.7.7 and 5.2, they recommend an update
to the latest version of the respective branches (4.7.8 and 5.3).

I emailed security-team@ earlier today with patches for the vuxml database,
and will get patches for 4.7.8 and 5.3 in the next day or two.

Nick
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: for understanding correctly -- Up-to-date - Upgread ..
    ... announcements of new security patches. ... > really easy to update ports with portupgrade because ports also have ... Yes -- security advisories will contain patches for the base system, ... I want to ask When I have high-profile production server Does ...
    (freebsd-questions)
  • Re: www/drupal4 and www/drupal5: Multiple security vulnerabilities
    ... 4.7.x and 5.x releases of the Drupal package. ... ports: www/drupal4 and www/drupal5. ... The following are the security advisories that were posted: ...
    (FreeBSD-Security)
  • Re: cvs tag for 5.2R
    ... The CVS tag for a -STABLE FreeBSD is still RELENG_4. ... You got 5.2-RELEASE with security advisories and patches. ...
    (comp.unix.bsd.freebsd.misc)