USN-4773-1

Source
https://ubuntu.com/security/notices/USN-4773-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4773-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4773-1
Related
Published
2021-03-15T20:17:24.844672Z
Modified
2021-03-15T20:17:24.844672Z
Summary
drupal7 vulnerabilities
Details

It was discovered that Drupal did not properly process certain input. An attacker could use this vulnerability to execute arbitrary code or completely compromise a Drupal site. (CVE-2018-7600, CVE-2018-7602)

It was discovered that password reset URLs in Drupal could be forged. An attacker could use this vulnerability to gain access to another user's account. This issue affected only Ubuntu 14.04 ESM. (CVE-2015-2559)

It was discovered that Drupal did not properly protect against open redirects. An attacker could use this vulnerability to send unsuspecting users to 3rd party sites and potentially carry out phishing attacks. This issue affected only Ubuntu 14.04 ESM. (CVE-2015-2749, CVE-2015-2750)

References

Affected packages

Ubuntu:Pro:14.04:LTS / drupal7

Package

Name
drupal7
Purl
pkg:deb/ubuntu/drupal7@7.26-1ubuntu0.1+esm1?arch=source&distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.26-1ubuntu0.1+esm1

Affected versions

7.*

7.23-1
7.24-1
7.24-2
7.26-1
7.26-1ubuntu0.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "7.26-1ubuntu0.1+esm1",
            "binary_name": "drupal7"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / drupal7

Package

Name
drupal7
Purl
pkg:deb/ubuntu/drupal7@7.44-1ubuntu1~16.04.0+esm1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.44-1ubuntu1~16.04.0+esm1

Affected versions

7.*

7.38-1
7.41-1
7.44-1ubuntu1~16.04.0

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "7.44-1ubuntu1~16.04.0+esm1",
            "binary_name": "drupal7"
        }
    ]
}