CVE-2007-4436

Publication date 20 August 2007

Last updated 17 July 2025


Ubuntu priority

Description

The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain project names via unspecified vectors; (3) obtain sensitive information via the statistics pages; and (4) read CVS project activity.

Status

Package Ubuntu Release Status
drupal 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected


Access our resources on patching vulnerabilities