{"id":"MGASA-2016-0413","summary":"Updated drupal packages fix security vulnerability","details":"Inconsistent name for term access query; information on taxonomy terms\nmight have been disclosed to unprivileged users (CVE-2016-9449).\n\nConfirmation forms allow external URLs to be injected (CVE-2016-9451).\n","modified":"2026-04-16T06:22:46.302760566Z","published":"2016-12-07T11:48:35Z","upstream":["CVE-2016-9449","CVE-2016-9451"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0413.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=19812"},{"type":"WEB","url":"https://www.drupal.org/SA-CORE-2016-005"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.45"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.45-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.46"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.46-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.47"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.47-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.48"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.48-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.49"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.49-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.50"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.50-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.51"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.51-release-notes"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.52"},{"type":"WEB","url":"https://www.drupal.org/drupal-7.52-release-notes"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/11/18/16"},{"type":"WEB","url":"https://lwn.net/Vulnerabilities/707038/"},{"type":"WEB","url":"https://lwn.net/Vulnerabilities/707041/"}],"affected":[{"package":{"name":"drupal","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/drupal?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.52-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0413.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}