PT-2014-6380 · Drupal · Drupal

Publicado

2014-09-30

·

Atualizado

2014-10-10

·

CVE-2014-5267

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x prior to 6.33 Drupal versions 7.x prior to 7.31
Description The issue allows remote attackers to have an unspecified impact via a crafted DOCTYPE declaration in an XRDS document, specifically affecting the modules/openid/xrds.inc file.
Recommendations For Drupal 6.x, update to version 6.33 or later. For Drupal 7.x, update to version 7.31 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5267
DSA-2999-1

Produtos afetados

Drupal