[Full-disclosure] [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue

From: Uwe Hermann (uwe_at_hermann-uwe.de)
Date: 06/03/05

  • Next message: andy mueller: "[Full-disclosure] (no subject)"
    Date: Fri, 3 Jun 2005 12:47:42 +0200
    To: bugtraq@securityfocus.com
    
    
    
    

    ----------------------------------------------------------------------------
    Drupal security advisory DRUPAL-SA-2005-001
    ----------------------------------------------------------------------------
    Advisory ID: DRUPAL-SA-2005-001
    Date: 2005-jun-01
    Security risk: highly critical
    Impact: system access
    Where: from remote
    Vulnerability: privilege escalation
    ----------------------------------------------------------------------------

    Description
    -----------
    The Drupal Security Team has found that the privilege system of Drupal can
    be circumvented in a very special case because an input check is not
    implemented properly.

    Versions affected
    -----------------
    Drupal 4.4.0, 4.4.1, 4.4.2
    Drupal 4.5.0, 4.5.1, 4.5.2
    Drupal 4.6.0

    Impact
    ------
    If public registration is allowed then it is possible for an attacker
    to obtain additional user roles. As a result, an attacker could grant
    himself administration privileges.

    Solution
    --------
    Either upgrade or disable public registration:
    - If you are running Drupal 4.4.x, then upgrade to Drupal 4.4.3.
    - If you are running Drupal 4.5.2, then upgrade to Drupal 4.5.3.
    - If you are running Drupal 4.6.0, then upgrade to Drupal 4.6.1.
    - If you cannot upgrade immediately, you can secure your site by
      disabling the public registration of Drupal accounts from Drupal's user
      administration screen. Log-in as an administrator, go to "administer >>
      users >> configure" and set the "Public registrations" option to "Only
      site administrators can create new user accounts".

    Contact
    -------
    The security contact for Drupal can be reached at security@drupal.org
    or using the form at http://drupal.org/contact.

    // Uwe Herman, on behalf of the Drupal Security Team.

    -- 
    Uwe Hermann <uwe@hermann-uwe.de>
    http://www.hermann-uwe.de                 | http://www.crazy-hacks.org
    http://www.it-services-uh.de              | http://www.phpmeat.org
    http://www.unmaintained-free-software.org | http://www.holsham-traders.de
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: andy mueller: "[Full-disclosure] (no subject)"

    Relevant Pages

    • [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue
      ... The Drupal Security Team has found that the privilege system of Drupal can ... If public registration is allowed then it is possible for an attacker ... If you are running Drupal 4.4.x, then upgrade to Drupal 4.4.3. ...
      (Bugtraq)
    • Re: ASP.NET Impersonation / delegation
      ... If your security guys will not even allow delegation, ... Bruce - I think this is a major right to grant to the ASPNet account. ... I have included a description on SE_TCB_NAME privilege from one of the MS ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: Event ID 577 & Failed Install of Microsoft Firewall Client
      ... NT Local Security Authority / Authentication Service ... Primary Domain: <domain or workgroup name> ... Client Domain: ... privilege to perform a privileged system service. ...
      (microsoft.public.security)
    • Re: Event ID 577 & Failed Install of Microsoft Firewall Client
      ... NT Local Security Authority / Authentication Service ... Primary Domain: <domain or workgroup name> ... Client Domain: ... privilege to perform a privileged system service. ...
      (microsoft.public.win2000.security)
    • Re: [Fwd: Re: How secure is Preupgrade? Answer: Not.]
      ... But it's not being marketed as an alternative to an Anaconda HTTP install with less downtime as the only improvement. ... It's being marketed as a safer alternative to a live upgrade with Yum, and as a faster, more convenient and less bandwidth-wasting alternative to downloading and burning DVD images. ... The article talks a lot about how Preupgrade is better than both a Yum upgrade and a DVD-based upgrade, but says very little about network-based Anaconda upgrades, and it's completely silent about the security aspect. ...
      (Fedora)

  • Quantcast