CVE-2009-3568

Publication date 6 October 2009

Last updated 24 July 2024


Ubuntu priority

Description

Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.

Read the notes from the security team

Status

Package Ubuntu Release Status
drupal5 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release
drupal6 9.04 jaunty
Not affected
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

drupal packages don't contain commentRSS