<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #759: [Security-news] SA-CONTRIB-2014-071 - FileField - Access bypass</title>
    <link>http://localhost:8080/trac/ticket/759</link>
    <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/node/2304561"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304561&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CONTRIB-2014-071
&lt;/li&gt;&lt;li&gt;Project: &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; (third-party module)
&lt;/li&gt;&lt;li&gt;Version: 6.x
&lt;/li&gt;&lt;li&gt;Date: 2014-July-16
&lt;/li&gt;&lt;li&gt;Security risk: Critical &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Exploitable from: Remote
&lt;/li&gt;&lt;li&gt;Vulnerability: Access bypass
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; module enables you to define and use fields that contain files.
&lt;/p&gt;
&lt;p&gt;
The module doesn't sufficiently check permission to view the attached file
when attaching a file that was previously uploaded. This could allow
attackers to gain access to private files.
&lt;/p&gt;
&lt;p&gt;
This vulnerability is mitigated by the fact that the attacker must have
permission to create or edit content with a file field.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; 6.x-3.x versions prior to 6.x-3.13.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Drupal core is not affected. If you do not use the contributed &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt;
module, there is nothing you need to do.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;If you use the &lt;a class="missing wiki"&gt;FileField?&lt;/a&gt; module for Drupal 6.x, upgrade to Filefield
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
6.x-3.13 &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;, and also update to Drupal core 6.32 &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; (see
SA-CORE-2014-003 &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt;).
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Nate Haug &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Ivan Ch &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;David Snopek &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; of the Drupal Security Team.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt;, and securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Follow the Drupal Security Team on Twitter at
&lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/filefield"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/filefield&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/node/2304517"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/node/2304517&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/drupal-6.32-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/drupal-6.32-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-003"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-003&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/35821"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/35821&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/556138"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/556138&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/266527"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/266527&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security/secure-configuration&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://twitter.com/drupalsecurity"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://twitter.com/drupalsecurity&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;_
Security-news mailing list
Security-news@…
Unsubscribe at &lt;a class="ext-link" href="https://lists.drupal.org/mailman/listinfo/security-news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.drupal.org/mailman/listinfo/security-news&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/759</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Wed, 16 Jul 2014 22:00:39 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/759#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/759#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I'll pick this up in the morning.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Wed, 16 Jul 2014 22:02:06 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/759#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/759#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.125&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I'll pick this up in the morning.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 29 Jul 2014 10:52:33 GMT</pubDate>
      <title>milestone set</title>
      <link>http://localhost:8080/trac/ticket/759#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/759#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;milestone&lt;/strong&gt;
                set to &lt;em&gt;Maintenance&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/759" title="maintenance: [Security-news] SA-CONTRIB-2014-071 - FileField - Access bypass (new)"&gt;paul&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This could allow attackers to gain access to private files.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I don't think we have any private files? However if there was a bot designed to exploit this bug and search for private files it wouldn't know this...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 31 Jul 2014 21:52:26 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/759#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/759#comment:4</guid>
      <description>
        &lt;p&gt;
Module updated. No problems to report.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>