[Full-disclosure] [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue

From: Uwe Hermann (uwe_at_hermann-uwe.de)
Date: 06/29/05

  • Next message: Christopher Kunz: "[Full-disclosure] Advisory 02/2005: Remote code execution in Serendipity"
    Date: Wed, 29 Jun 2005 23:39:26 +0200
    To: bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk, phpsec@phparch.com
    
    
    
    

    ----------------------------------------------------------------------------
    Drupal security advisory DRUPAL-SA-2005-003
    ----------------------------------------------------------------------------
    Advisory ID: DRUPAL-SA-2005-003
    Date: 2005-jun-29
    Security risk: highly critical
    Impact: system access
    Where: from remote
    Vulnerability: arbitrary PHP code execution
    ----------------------------------------------------------------------------

    Description
    -----------
    A flaw has been discovered in the third-party XML-RPC library included with
    Drupal. An attacker could execute arbitrary PHP code on a target site.

    Versions affected
    -----------------
    All versions

    Solution
    --------
    Either remove the XML-RPC server, or upgrade to the latest Drupal version:
    - If you cannot upgrade immediately, you can secure your site by removing
      the XML-RPC server: simply remove the file 'xmlrpc.php' in the root of
      your Drupal directory.
    - If you are running Drupal 4.5.x, then upgrade to Drupal 4.5.4.
    - If you are running Drupal 4.6.x, then upgrade to Drupal 4.6.2.

    Contact
    -------
    The security contact for Drupal can be reached at security@drupal.org
    or using the form at http://drupal.org/contact.

    // Uwe Hermann, on behalf of the Drupal Security Team.

    -- 
    Uwe Hermann <uwe@hermann-uwe.de>
    http://www.hermann-uwe.de                 | http://www.crazy-hacks.org
    http://www.it-services-uh.de              | http://www.phpmeat.org
    http://www.unmaintained-free-software.org | http://www.holsham-traders.de
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: Christopher Kunz: "[Full-disclosure] Advisory 02/2005: Remote code execution in Serendipity"

    Relevant Pages